Fallos del tipo CWE-20

5441 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2021-3442—A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripEPSS 0.5%CVE-2025-27494CRITICALA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < VEPSS 0.5%CVE-2023-35163MEDIUMVega's validators able to submit duplicate transactions EPSS 0.5%CVE-2025-5326MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 verifyToken deserializationEPSS 0.5%CVE-2026-49830MEDIUMDSpace: ORE resource URI does not validate scheme for non-web resourcesEPSS 0.5%CVE-2022-24926MEDIUMImproper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victimEPSS 0.5%CVE-2023-22963MEDIUMThe personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-9]$ regular expressiEPSS 0.5%CVE-2026-13794HIGHInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker whEPSS 0.5%CVE-2026-48188CRITICALSQL Injection via MySQL Quote MethodEPSS 0.5%CVE-2026-26452HIGHccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when pEPSS 0.5%CVE-2026-42566HIGHMeshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failureEPSS 0.5%CVE-2026-62295HIGHHAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2026-36501HIGHAn issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.5%CVE-2024-7005HIGHInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.5%CVE-2026-61634NONERabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_maxEPSS 0.5%CVE-2022-31172HIGHOpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signersEPSS 0.5%CVE-2025-60012MEDIUMApache Livy: Restrict file accessEPSS 0.5%CVE-2026-40454HIGHApache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server dataEPSS 0.5%CVE-2024-37917HIGHPexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a EPSS 0.5%CVE-2026-62296HIGHHAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%