Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-91842LOWOpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserializationEPSS 0.4%CVE-2025-2305HIGHLocal file inclusion vulnerability in LIVE CONTRACTEPSS 0.4%CVE-2026-3912HIGHTIBCO ActiveMatrix BusinessWorks Injection VulnerabilityEPSS 0.4%CVE-2023-4553MEDIUMUnauthenticated Access to AppBuilder Configuration FilesEPSS 0.4%CVE-2025-54785HIGHSuiteCRM is Vulnerable to PHP Object Injection in ReportsEPSS 0.4%CVE-2026-30576HIGHA Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application faEPSS 0.4%CVE-2026-4982HIGHUnauthorized access to chat contentsEPSS 0.4%CVE-2026-13602HIGHSession takeover vulnerabilityEPSS 0.4%CVE-2023-38057MEDIUMXSS stored in survey answersEPSS 0.4%CVE-2024-37406HIGHIn Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domEPSS 0.4%CVE-2026-25126HIGHPolarLearn's unvalidated vote direction allows vote count manipulationEPSS 0.4%CVE-2015-6563MEDIUMThe monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX reEPSS 0.4%CVE-2026-54728MEDIUMbunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWebEPSS 0.4%CVE-2026-33369MEDIUMZimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operatioEPSS 0.4%CVE-2026-67969HIGHAn issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a craftEPSS 0.4%CVE-2026-46669HIGH`openvm-pairing` pairing check missing proper subfield check on scaling factorEPSS 0.4%CVE-2025-3622MEDIUMXorbits Inference model.py load deserializationEPSS 0.4%CVE-2024-20334MEDIUMA vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attaEPSS 0.4%CVE-2023-3434MEDIUMQRC Handler without Input Validation in JamiEPSS 0.4%CVE-2026-53541MEDIUMOliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input FilteringEPSS 0.4%