Fallos del tipo CWE-20

5439 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-0683HIGHA valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.EPSS 0.6%CVE-2026-21247HIGHWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-33964HIGHmx-chain-go does not treat invalid transaction with wrong username correctlyEPSS 0.6%CVE-2025-6279MEDIUMUpsonic Pickle add_tool cloudpickle.loads deserializationEPSS 0.6%CVE-2020-15201MEDIUMHeap buffer overflow in TensorflowEPSS 0.6%CVE-2023-31011MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploitEPSS 0.6%CVE-2021-25684HIGHapport can be stalled by reading a FIFOEPSS 0.6%CVE-2024-20464HIGHA vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attackerEPSS 0.6%CVE-2026-3294HIGHAuthentication Logic Vulnerability on Multiple TP-Link Range ExtendersEPSS 0.6%CVE-2023-49252HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change withouEPSS 0.6%CVE-2026-29905MEDIUMKirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformedEPSS 0.6%CVE-2023-29457MEDIUMInsufficient validation of Action form input fieldsEPSS 0.6%CVE-2023-49095HIGHnexkey allows arbitrary users to impersonate any remote user due to missing signature validationEPSS 0.6%CVE-2014-5398—Schneider Electric Wonderware Input ValidationEPSS 0.6%CVE-2024-2199MEDIUM389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.cEPSS 0.6%CVE-2026-54133CRITICALjmespath.php has CompilerRuntime code injection via unescaped function namesEPSS 0.6%CVE-2024-40721HIGHCHANGING Information Technology TCBServiSign Windows Version - Improper Input ValidationEPSS 0.6%CVE-2025-66918HIGHedoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.EPSS 0.6%CVE-2026-19826MEDIUMalldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserializationEPSS 0.6%CVE-2026-75987MEDIUMSPLWare esProc SocketData.java ObjectInputStream.readUnshared deserializationEPSS 0.6%