Fallos del tipo CWE-20

5450 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2020-12521MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.EPSS 0.5%CVE-2023-40165HIGHUnauthorized gem replacement for full names ending in numbers on rubygems.orgEPSS 0.5%CVE-2023-21767HIGHWindows Overlay Filter Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2020-3487HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service VulnerabilitiesEPSS 0.5%CVE-2026-27304CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2026-26310MEDIUMCrash for scoped ip address in Envoy during DNSEPSS 0.5%CVE-2026-12954HIGHMapster WP Maps <= 1.23.0 - Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' ParameterEPSS 0.5%CVE-2026-49095HIGHImproper Input Validation in Kibana Fleet Leading to Privilege EscalationEPSS 0.5%CVE-2024-47857CRITICALSSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSHEPSS 0.5%CVE-2025-20148HIGHCisco Secure Firewall Management Center HTML Injection VulnerabilityEPSS 0.5%CVE-2025-9066HIGHRockwell Automation FactoryTalk® ViewPoint XXE to Denial-of-Service VulnerabilityEPSS 0.5%CVE-2020-3434MEDIUMCisco AnyConnect Secure Mobility Client for Windows Denial of Service VulnerabilityEPSS 0.5%CVE-2024-32645MEDIUMvyper performs incorrect topic logging in raw_logEPSS 0.5%CVE-2021-39256MEDIUMA crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.EPSS 0.5%CVE-2026-65336MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65340MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-23886MEDIUMSwift W3C TraceContext has malformed HTTP header that can cause a crashEPSS 0.5%CVE-2020-3428HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WLAN Local Profiling Denial of Service VulnerabilityEPSS 0.5%CVE-2025-71007HIGHAn input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) vEPSS 0.5%CVE-2024-50343LOWIncorrect response from Validator when input ends with `\n` in symfony/validatorEPSS 0.5%