Fallos del tipo CWE-20

5451 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-4027HIGHUndertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacksEPSS 0.4%CVE-2022-47909MEDIUMLQL Injection in Livestatus HTTP headersEPSS 0.4%CVE-2026-48774HIGHProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contractEPSS 0.4%CVE-2026-45628CRITICALDokploy: Command Injection via Unescaped Branch Fields in Deployment PipelineEPSS 0.4%CVE-2026-17664MEDIUMInsufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised tEPSS 0.4%CVE-2026-79410HIGHImproper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce theiEPSS 0.4%CVE-2025-60537MEDIUMImproper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute EPSS 0.4%CVE-2026-9211MEDIUMCertain NETGEAR routers allow unauthenticated users to gain control of the routerEPSS 0.4%CVE-2026-4519HIGHwebbrowser.open() allows leading dashes in URLsEPSS 0.4%CVE-2017-14025—An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identifiedEPSS 0.4%CVE-2025-61235CRITICALAn issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields cEPSS 0.4%CVE-2025-32077MEDIUMXSSes in Extension:SimpleCalendarEPSS 0.4%CVE-2025-24319HIGHBIG-IP Next Central Manager vulnerabilityEPSS 0.4%CVE-2025-50494HIGHImproper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackersEPSS 0.4%CVE-2026-52780CRITICALOpenProject: Cache store poisoning leads to Remote Code Execution (RCE)EPSS 0.4%CVE-2026-95659MEDIUMMISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind ThreadEPSS 0.4%CVE-2026-65604HIGHSkipper Incomplete Fix for CVE-2026-50197 Policy BypassEPSS 0.4%CVE-2018-15368—Cisco IOS XE Software Privileged EXEC Mode Root Shell Access VulnerabilityEPSS 0.4%CVE-2026-50569MEDIUMFission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checksEPSS 0.4%CVE-2024-39780HIGHUse of unsafe yaml load in dynparamEPSS 0.4%