Fallos del tipo CWE-20

5441 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-3429MEDIUMA denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an opeEPSS 0.5%CVE-2023-49796MEDIUMMindsDB Arbitrary File Write vulnerabilityEPSS 0.5%CVE-2024-7974HIGHInsufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruptEPSS 0.5%CVE-2025-64385CRITICALINCORRECT SECURITY VALIDATION IN SENDING UDP FRAMESEPSS 0.5%CVE-2023-7060HIGHMissing Security Control in Zephyr OS IP Packet HandlingEPSS 0.5%CVE-2024-39950HIGHA vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities toEPSS 0.5%CVE-2026-48284CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2025-6444MEDIUMServiceStack GetErrorResponse Improper Input Validation NTLM Relay VulnerabilityEPSS 0.5%CVE-2026-84469HIGHfastify vulnerable to request validation bypass via skipped boolean false schemasEPSS 0.5%CVE-2026-47928CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2025-0841MEDIUMAridius XYZ News loadMore deserializationEPSS 0.5%CVE-2022-34436LOW Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuraEPSS 0.5%CVE-2024-27931MEDIUMInsufficient permission checking in `Deno.makeTemp*` APIsEPSS 0.5%CVE-2022-34885HIGHAn improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbEPSS 0.5%CVE-2025-59952HIGHminio-java Client XML Tag is Vulnerable to Value SubstitutionEPSS 0.5%CVE-2026-54207MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionalityEPSS 0.5%CVE-2026-54206MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionalityEPSS 0.5%CVE-2026-54205MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionalityEPSS 0.5%CVE-2025-27494CRITICALA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < VEPSS 0.5%CVE-2021-3442—A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripEPSS 0.5%