Fallos del tipo CWE-20

5443 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-22243MEDIUMJunos OS: XPath Injection vulnerability in J-WebEPSS 0.5%CVE-2026-7165CRITICALMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.5%CVE-2024-4003MEDIUMEssential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-47369CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 0.5%CVE-2026-13706NONEUrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWGEPSS 0.5%CVE-2025-15545HIGHInsufficient Backup File Upload Input Validation on TP-Link Archer RE605XEPSS 0.5%CVE-2026-19913HIGHCVE-2026-19913EPSS 0.5%CVE-2026-33029MEDIUMNginx UI: DoS via Negative Integer Input in Logrotate IntervalEPSS 0.5%CVE-2026-27306HIGHColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2026-0878HIGHSandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2022-44556HIGHMissing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability. EPSS 0.5%CVE-2025-6625HIGHCWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to theEPSS 0.5%CVE-2025-61582HIGHTs3 Manager: Unauthenticated Denial of Service possible through specially crafted Unicode inputEPSS 0.5%CVE-2026-34760MEDIUMvLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI ModelsEPSS 0.5%CVE-2022-23814MEDIUMFailure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confideEPSS 0.5%CVE-2025-59198MEDIUMWindows Search Service Denial of Service VulnerabilityEPSS 0.5%CVE-2022-41898MEDIUM`CHECK` fail via inputs in `SparseFillEmptyRowsGrad` in TensorflowEPSS 0.5%CVE-2022-48356—The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause fEPSS 0.5%CVE-2022-41901MEDIUM`CHECK_EQ` fail via input in `SparseMatrixNNZ` in TensorflowEPSS 0.5%CVE-2022-41896MEDIUM`tf.raw_ops.Mfcc` crashes in TensorflowEPSS 0.5%