Fallos del tipo CWE-20

5430 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-22935HIGHSPL Command Safeguards Bypass via the ‘display.page.search.patterns.sensitivity’ Search Parameter in Splunk EnterpriseEPSS 0.6%CVE-2024-9257MEDIUMLogsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion VulnerabilityEPSS 0.6%CVE-2026-12128MEDIUMPinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' ParameterEPSS 0.6%CVE-2024-0031CRITICALIn attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This couEPSS 0.6%CVE-2026-24406HIGHiccDEV has Heap Buffer Overflow in CIccTagNamedColor2::SetSize()EPSS 0.6%CVE-2025-27489HIGHAzure Local Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-24405HIGHiccDEV has Heap Buffer Overflow in CIccMpeCalculator::Read()EPSS 0.6%CVE-2026-24412HIGHiccDEV has Heap Buffer Overflow in icCurvesFromXml()EPSS 0.6%CVE-2022-45770HIGHImproper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.EPSS 0.6%CVE-2025-48490MEDIUMLaravel Rest Api has a Search Validation BypassEPSS 0.6%CVE-2024-28226HIGHFs has an improper input validation vulnerabilityEPSS 0.6%CVE-2022-23766HIGHBigFileAgent arbitrary file execution vulnerabilityEPSS 0.6%CVE-2023-36719HIGHMicrosoft Speech Application Programming Interface (SAPI) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-4287HIGHImproper Input Validation in mintplex-labs/anything-llmEPSS 0.6%CVE-2026-37460HIGHMissing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cauEPSS 0.6%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.6%CVE-2023-27984HIGHA CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to rEPSS 0.6%CVE-2021-27418MEDIUMGE UR family input validationEPSS 0.6%CVE-2025-60938HIGHEmoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitraryEPSS 0.6%CVE-2026-49098MEDIUMApache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topicEPSS 0.6%