Fallos del tipo CWE-20

5450 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-57130HIGHPraisonAI: IMAP Command Injection via Unsanitized Email Search ParametersEPSS 0.5%CVE-2026-24407HIGHiccDEV has Undefined Behavior in icSigCalcOp()EPSS 0.5%CVE-2026-24403HIGHiccDEV Undefined Behavior in CIccProfile::CheckHeader() Leads to Integer OverflowEPSS 0.5%CVE-2026-24404HIGHiccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()EPSS 0.5%CVE-2026-47219HIGHfind-my-way is Vulnerable to DDoS with HTTP2EPSS 0.5%CVE-2026-30064HIGHImproper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of ServiEPSS 0.5%CVE-2026-51606HIGHAn improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminateEPSS 0.5%CVE-2026-45291HIGHCloudburst Network erroneously handles invalid connectionsEPSS 0.5%CVE-2026-82003HIGHAdobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2024-27613HIGHNumbas editor before 7.3 mishandles reading of themes and extensions.EPSS 0.5%CVE-2025-55679MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-67978HIGHAn issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN framEPSS 0.5%CVE-2026-42544HIGHGranian: Unauthenticated DoS via WebSocket subprotocol header panicEPSS 0.5%CVE-2026-55973HIGH'dns-error-reporting: yes' leads to stack buffer overflowEPSS 0.5%CVE-2026-30058HIGHImproper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a EPSS 0.5%CVE-2026-48110HIGHRussh: SSH message fields were decoded through allocation-first parsers before field-specific boundsEPSS 0.5%CVE-2026-46679HIGHlibp2p: Memory DoS via subscription flood of unique topicsEPSS 0.5%CVE-2026-30068HIGHImproper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial ofEPSS 0.5%CVE-2023-21767HIGHWindows Overlay Filter Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2020-12521MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.EPSS 0.5%