Fallos del tipo CWE-20

5439 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2018-0306—A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attackEPSS 0.6%CVE-2026-78147MEDIUMggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserializationEPSS 0.6%CVE-2020-3314MEDIUMCisco AMP for Endpoints Mac Connector Software File Scan Denial of Service VulnerabilityEPSS 0.6%CVE-2025-61611HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegeEPSS 0.6%CVE-2025-1217MEDIUMHeader parser of http stream wrapper does not handle folded headersEPSS 0.6%CVE-2026-62647CRITICALA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevantEPSS 0.6%CVE-2023-36888MEDIUMMicrosoft Edge for Android (Chromium-based) Tampering VulnerabilityEPSS 0.6%CVE-2026-34685LOWAdobe Commerce | Improper Input Validation (CWE-20)EPSS 0.6%CVE-2026-40068HIGHClaude Code arbitrary code execution via git worktree commondir trust dialog bypassEPSS 0.6%CVE-2025-49554HIGHAdobe Commerce | Improper Input Validation (CWE-20)EPSS 0.6%CVE-2026-29046CRITICALTinyWeb: HTTP Header Control Character Injection into CGI EnvironmentEPSS 0.6%CVE-2024-22768HIGHHitron Systems DVR HVR-4781 Improper Input Validation Vulnerability EPSS 0.6%CVE-2026-46584LOWApache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parametersEPSS 0.6%CVE-2026-67234LOWRabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism preferenceEPSS 0.6%CVE-2024-25973MEDIUMMultiple Stored Cross-Site Scripting VulnerabilitiesEPSS 0.6%CVE-2024-0955MEDIUMStored XSS vulnerabilityEPSS 0.6%CVE-2026-28797HIGHRAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" ComponentEPSS 0.6%CVE-2024-39948HIGHA vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, cEPSS 0.6%CVE-2024-39944HIGHA vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, caEPSS 0.6%CVE-2024-39949HIGHA vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, cEPSS 0.6%