Fallos del tipo CWE-20

5450 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2025-66960HIGHAn issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads EPSS 0.4%CVE-2021-39251MEDIUMA crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.EPSS 0.4%CVE-2025-20389MEDIUMImproper Input Validation in "label" column field in Splunk Secure Gateway AppEPSS 0.4%CVE-2021-33285MEDIUMIn NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap bufferEPSS 0.4%CVE-2026-34207HIGHTypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request ValidationEPSS 0.4%CVE-2020-16127LOWaccountsservice .pam_environment infinite loopEPSS 0.4%CVE-2024-41839LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.4%CVE-2025-54134HIGHHAX CMS NodeJs's Improper Error Handling Leads to Denial of ServiceEPSS 0.4%CVE-2021-0162HIGHImproper input validation in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticaEPSS 0.4%CVE-2021-33287MEDIUMIn NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow cEPSS 0.4%CVE-2023-22937MEDIUMUnnecessary File Extensions Allowed by Lookup Table Uploads in Splunk EnterpriseEPSS 0.4%CVE-2025-69250MEDIUMfree5GC has Improper Error Handling in UDM, Leading to Information ExposureEPSS 0.4%CVE-2021-0163HIGHImproper Validation of Consistency within input in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 mayEPSS 0.4%CVE-2026-8527HIGHInsufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrEPSS 0.4%CVE-2018-5270HIGHIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsEPSS 0.4%CVE-2026-62828MEDIUMMicrosoft Edge for Android (Chromium-based) Tampering VulnerabilityEPSS 0.4%CVE-2026-5879HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbiEPSS 0.4%CVE-2025-4635MEDIUMRemote Code ExecutionEPSS 0.4%CVE-2022-30784MEDIUMA crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.EPSS 0.4%CVE-2026-45492MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 0.4%