Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-5421LOW Possible XSS execution in customer information EPSS 0.4%CVE-2026-97182MEDIUMhalo-dev Halo SpEL ReplyNotificationSubscriptionHelper.java neutralizationEPSS 0.4%CVE-2018-0122—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenEPSS 0.4%CVE-2026-14087HIGHHeap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer EPSS 0.4%CVE-2023-48425CRITICALU-Boot vulnerability resulting in persistent Code Execution EPSS 0.4%CVE-2026-22047HIGHiccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cppEPSS 0.4%CVE-2026-58683HIGHIn IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code executiEPSS 0.4%CVE-2023-24304HIGHImproper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF fileEPSS 0.4%CVE-2026-95341HIGHImproper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer procEPSS 0.4%CVE-2025-31135MEDIUMGo-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple timesEPSS 0.4%CVE-2026-95276HIGHImproper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proceEPSS 0.4%CVE-2026-45642LOWMicrosoft Azure Attestation service and Device Health Attestation Service Spoofing VulnerabilityEPSS 0.4%CVE-2025-13805MEDIUMnutzam NutzBoot LiteRpc-Serializer HttpServletRpcEndpoint.java getInputStream deserializationEPSS 0.4%CVE-2026-56974HIGHIn Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remEPSS 0.4%CVE-2023-46047HIGHAn issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: EPSS 0.4%CVE-2024-7023HIGHInsufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation viaEPSS 0.4%CVE-2024-33996MEDIUMmoodle: broken access control when setting calendar event typeEPSS 0.4%CVE-2025-66974HIGHAn issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a DenialEPSS 0.4%CVE-2026-54911MEDIUMUltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()EPSS 0.4%CVE-2024-32990MEDIUMPermission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect EPSS 0.4%