Fallos del tipo CWE-20

5450 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-65336MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2024-32645MEDIUMvyper performs incorrect topic logging in raw_logEPSS 0.5%CVE-2021-26639HIGHWISA Smart Wing CMS File Download VulnerabilityEPSS 0.5%CVE-2026-59109HIGHZalktis: SQL injection via partner-controlled fields in imported e-invoicesEPSS 0.5%CVE-2021-25682HIGHapport improperly parses /proc/pid/statusEPSS 0.5%CVE-2024-1246LOWConcrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import FeatureEPSS 0.5%CVE-2021-39263MEDIUMA crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < EPSS 0.5%CVE-2026-5659MEDIUMpytries datrie trie File datrie.pyx Trie.__setstate__ deserializationEPSS 0.5%CVE-2023-20134MEDIUMCisco Webex Meetings Web UI VulnerabilitiesEPSS 0.5%CVE-2026-94093MEDIUMDLR-RM stable-baselines3 save_util.py VecNormalize.load deserializationEPSS 0.5%CVE-2021-39261MEDIUMA crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.EPSS 0.5%CVE-2023-34983MEDIUMImproper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthEPSS 0.5%CVE-2025-3116HIGHCWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends specialEPSS 0.5%CVE-2023-41300—Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the systeEPSS 0.5%CVE-2021-0214MEDIUMJunos OS: Denial of Service in ppmd upon receipt of malformed packetEPSS 0.5%CVE-2019-15971MEDIUMCisco Email Security Appliance MP3 Content Filter Bypass VulnerabilityEPSS 0.5%CVE-2024-39281MEDIUMUnbounded allocation in ctl(4) CAM Target LayerEPSS 0.5%CVE-2025-23268HIGHNVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may cause an improper input validation issue. EPSS 0.5%CVE-2026-55554LOWDompdf: Chroot Validation BypassEPSS 0.5%CVE-2026-33692HIGHAVideo Has Unauthenticated .env File Exposure via Official Docker Compose ConfigurationEPSS 0.5%