Fallos del tipo CWE-20

5443 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-41896MEDIUM`tf.raw_ops.Mfcc` crashes in TensorflowEPSS 0.5%CVE-2022-41901MEDIUM`CHECK_EQ` fail via input in `SparseMatrixNNZ` in TensorflowEPSS 0.5%CVE-2022-51017HIGHPocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin DataEPSS 0.5%CVE-2026-54694CRITICALNationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account TakeoverEPSS 0.5%CVE-2025-62455HIGHMicrosoft Message Queuing (MSMQ) Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2021-35268MEDIUMIn NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow EPSS 0.5%CVE-2022-41888MEDIUMUnckecked rank size in `tf.image.generate_bounding_box_proposals` in TensorflowEPSS 0.5%CVE-2021-25738MEDIUMCode exec via yaml parsingEPSS 0.5%CVE-2025-50233MEDIUMA vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of tEPSS 0.5%CVE-2026-9212MEDIUMInsufficient authentication and input validation in certain NETGEAR productsEPSS 0.5%CVE-2026-63734MEDIUMSurrealDB before 3.2.0 Denial of Service via malformed SurrealML importEPSS 0.5%CVE-2026-56151MEDIUMImproper Input Validation in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-30077HIGHOpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistEPSS 0.5%CVE-2025-50178MEDIUMGitForge.jl lacks validation for user provided fieldsEPSS 0.5%CVE-2026-26063HIGHCediPay Affected by Improper Input Validation in Payment ProcessingEPSS 0.5%CVE-2026-73513HIGHEnvoy: oghttp2 upstream trailers incorrect handlingEPSS 0.5%CVE-2025-52569MEDIUMGitHub.jl lacks validation for user-provided fieldsEPSS 0.5%CVE-2026-56349MEDIUMn8n - Guardrail Node Bypass via Crafted InputEPSS 0.5%CVE-2026-47931HIGHColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2025-58175MEDIUMGeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity ResolutionEPSS 0.5%