Fallos del tipo CWE-20

5439 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-6937MEDIUMImproper (D)TLS key boundary enforcementEPSS 0.5%CVE-2025-43427MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, EPSS 0.5%CVE-2022-39376LOWImproper input validation on emails links in GLPIEPSS 0.5%CVE-2022-34435LOW Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuraEPSS 0.5%CVE-2025-5679MEDIUMShenzhen Dashi Tongzhou Information Technology AgileBPM SysToolsController.java parseStrByFreeMarker deserializationEPSS 0.5%CVE-2020-6020—Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40EPSS 0.5%CVE-2026-24733MEDIUMApache Tomcat: Security constraint bypass with HTTP/0.9EPSS 0.5%CVE-2023-45805HIGHTrojan Lockfilein pdmEPSS 0.5%CVE-2025-12305MEDIUMquequnlong shiyi-blog Job SysJobController.java deserializationEPSS 0.5%CVE-2024-29461MEDIUMAn issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component.EPSS 0.5%CVE-2024-48919CRITICALRCE via Prompt Injection Into Cursor's Terminal Cmd-KEPSS 0.5%CVE-2024-32755CRITICALAmerican Dynamics Illustra Essentials Gen 4 - Log Filter Input ValidationEPSS 0.5%CVE-2023-22439LOW Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) caEPSS 0.5%CVE-2026-28960HIGHA denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker mEPSS 0.5%CVE-2022-35973MEDIUMSegfault in `QuantizedMatMul` in TensorFlowEPSS 0.5%CVE-2024-10944HIGHFactoryTalk® Updater Remote Code ExecutionEPSS 0.5%CVE-2022-35974MEDIUMSegfault in `QuantizeDownAndShrinkRange` in TensorFlowEPSS 0.5%CVE-2022-36017MEDIUMSegfault in `Requantize` in TensorFlowEPSS 0.5%CVE-2022-35970MEDIUMSegfault in `QuantizedInstanceNorm` in TensorFlowEPSS 0.5%CVE-2022-35986MEDIUMSegfault in `RaggedBincount` in TensorFlowEPSS 0.5%