Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-7992HIGHInsufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who coEPSS 0.4%CVE-2026-44425MEDIUMShellHub: Crash-DoS via field injection in filter and sort-by parametersEPSS 0.4%CVE-2025-0958MEDIUMUltimate WordPress Auction Plugin <= 4.2.9 - Missing Authorization to Arbitrary Post DeletionEPSS 0.4%CVE-2026-24411HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlSegmentedCurve::ToXml()EPSS 0.4%CVE-2024-21590HIGHJunos OS Evolved: Packets which are not destined to the device can reach the REEPSS 0.4%CVE-2024-3676HIGHThe Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unEPSS 0.4%CVE-2022-33719HIGHImproper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.EPSS 0.4%CVE-2025-52891MEDIUMModSecurity empty XML tag causes segmentation faultEPSS 0.4%CVE-2026-7317LOWGrav CMS Cache Value FileCache.php doGet deserializationEPSS 0.4%CVE-2022-39863LOWIntent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permissiEPSS 0.4%CVE-2025-53076MEDIUMImproper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.EPSS 0.4%CVE-2024-45761MEDIUMDell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileEPSS 0.4%CVE-2025-26780HIGHAn issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a DenialEPSS 0.4%CVE-2025-66786HIGHOpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send maliEPSS 0.4%CVE-2026-24204MEDIUMNVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit EPSS 0.4%CVE-2026-94445HIGHMalicious user input may lead to RCE in golang.org/x/playgroundEPSS 0.4%CVE-2023-21631HIGHImproper Input Validation in ModemEPSS 0.4%CVE-2024-12014LOWPath Traversal vulnerability in eSignaViewer Allow Unauthorized File AccessEPSS 0.4%CVE-2026-24409HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml()EPSS 0.4%CVE-2026-24410HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccProfileXml::ParseBasic()EPSS 0.4%