Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-5500HIGHImproper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication BypassEPSS 0.4%CVE-2025-3068HIGHInappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege esEPSS 0.4%CVE-2017-12338—A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary filEPSS 0.4%CVE-2025-63095MEDIUMImproper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a DeEPSS 0.4%CVE-2022-40276MEDIUMZettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious maEPSS 0.4%CVE-2026-45013HIGHApostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input ValidationEPSS 0.4%CVE-2026-88261MEDIUMImproper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.EPSS 0.4%CVE-2023-54392HIGHPocketMine-MP before 4.22.3 Denial of Service via BlockActorDataPacketEPSS 0.4%CVE-2025-23041MEDIUMShort and Long Answer Fields Are Not Validated Server-Side For Maximum Length in Umbraco.FormsEPSS 0.4%CVE-2023-7240MEDIUMBroken Access Control leading to SSRF in NetIQ Identity ConsoleEPSS 0.4%CVE-2022-1798HIGHPath Traversal vulnerability in KubevirtEPSS 0.4%CVE-2024-58380HIGHPocketMine-MP before 5.11.2 Denial of Service via BookEditPacketEPSS 0.4%CVE-2025-13587MEDIUMTwo Factor (2FA) Authentication via Email <= 1.9.8 - Two-Factor Authentication Bypass via tokenEPSS 0.4%CVE-2025-0051HIGHFlashArray DOS VulnerabilityEPSS 0.4%CVE-2024-2867MEDIUMPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-97869LOWlangchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserializationEPSS 0.4%CVE-2026-21679HIGHiccDEV has heap-buffer-overflow vulnerability in CIccLocalizedUnicode::GetText()EPSS 0.4%CVE-2024-52593MEDIUMMissing validation allows spoofed "origin" links in MisskeyEPSS 0.4%CVE-2026-43678MEDIUMAn unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent afEPSS 0.4%CVE-2026-97182MEDIUMhalo-dev Halo SpEL ReplyNotificationSubscriptionHelper.java neutralizationEPSS 0.4%