Fallos del tipo CWE-20

5439 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-94379MEDIUMMISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP)EPSS 0.6%CVE-2026-42809CRITICALApache Polaris: staged table creation could vend storage credentials for unvalidated locationsEPSS 0.6%CVE-2026-2555LOWJeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZip deserializationEPSS 0.6%CVE-2023-32484CRITICAL Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerabilitEPSS 0.6%CVE-2026-59954HIGHApollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingEPSS 0.6%CVE-2026-59955HIGHApollo ConfigService access key authentication bypass via raw config file appId parsingEPSS 0.6%CVE-2026-1691MEDIUMbolo-solo SnakeYAML BackupService.java importMarkdownsSync deserializationEPSS 0.6%CVE-2025-43494HIGHA mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.EPSS 0.6%CVE-2024-21544HIGHVersions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the seEPSS 0.6%CVE-2024-38359MEDIUMLightning Network Daemon Onion BombEPSS 0.6%CVE-2024-42531CRITICALEzviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packetsEPSS 0.6%CVE-2025-43458MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iEPSS 0.6%CVE-2020-3486HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service VulnerabilitiesEPSS 0.6%CVE-2026-35433HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-32177HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-23549MEDIUMDiscourse vulnerable to bypass of post max_length using HTML commentsEPSS 0.6%CVE-2023-29454MEDIUMPersistent XSS in the user formEPSS 0.6%CVE-2024-52815HIGHSynapse allows a a malformed invite to break the invitee's `/sync`EPSS 0.6%CVE-2026-54204HIGHTeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionalityEPSS 0.6%CVE-2023-0683HIGHA valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.EPSS 0.6%