Fallos del tipo CWE-20

5441 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-37917HIGHPexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a EPSS 0.5%CVE-2021-44545MEDIUMImproper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentialEPSS 0.5%CVE-2023-39405—Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps EPSS 0.5%CVE-2025-4905MEDIUMiop-apl-uw basestation3 QC.py load_qc_pickl deserializationEPSS 0.5%CVE-2024-2689MEDIUMDenial of Service if invalid UTF-8 sentEPSS 0.5%CVE-2025-8963MEDIUMjeecgboot JimuReport Data Large Screen Template testConnection deserializationEPSS 0.5%CVE-2026-20303CRITICALCisco Catalyst SD-WAN Security Hardening Release - Input Validation VulnerabilitiesEPSS 0.5%CVE-2026-45352MEDIUMcpp-httplib DoS: Negative chunk-size in chunked Transfer-EncodingEPSS 0.5%CVE-2025-47281HIGHKyverno's Improper JMESPath Variable Evaluation Leads to Denial of ServiceEPSS 0.5%CVE-2026-30575HIGHA Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application faEPSS 0.5%CVE-2026-49840CRITICALFreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsingEPSS 0.5%CVE-2025-5552MEDIUMChestnutCMS API Endpoint exec deserializationEPSS 0.5%CVE-2023-31162MEDIUMImproper Input Validation in Web InterfaceEPSS 0.5%CVE-2024-22199CRITICALDjango Template Engine Vulnerable to XSSEPSS 0.5%CVE-2026-90575MEDIUMPHPGurukul Small CRM Login Success login.php unserialize deserializationEPSS 0.5%CVE-2025-3250MEDIUMelunez eladmin Maintenance Management Module testConnect deserializationEPSS 0.5%CVE-2025-54247MEDIUMAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2026-42553HIGHCinny: Access token disclosure via invalidated emoji pack avatar URL in service workerEPSS 0.5%CVE-2022-41908MEDIUM`CHECK` fail via inputs in `PyFunc` in TensorflowEPSS 0.5%CVE-2025-1734MEDIUMStreams HTTP wrapper does not fail for headers with invalid name and no colonEPSS 0.5%