Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-47210MEDIUMImproper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user tEPSS 0.4%CVE-2026-33769LOWAstro: Remote allowlist bypass via unanchored matchPathname wildcardEPSS 0.4%CVE-2026-61711MEDIUMBuildKit: Custom frontend could bypass Seccomp/AppArmorEPSS 0.4%CVE-2026-13968HIGHInsufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a useEPSS 0.4%CVE-2017-12286—A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from EPSS 0.4%CVE-2022-42800HIGHThis issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 EPSS 0.4%CVE-2017-12252—A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attacEPSS 0.4%CVE-2026-15771MEDIUMInsufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had coEPSS 0.4%CVE-2025-15453MEDIUMmilvus HTTP Endpoint expr.go expr.Exec deserializationEPSS 0.4%CVE-2025-46047MEDIUMA User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers toEPSS 0.4%CVE-2025-62162HIGHcel-rust May Panic During Parsing of Invalid CEL ExpressionsEPSS 0.4%CVE-2026-5473LOWNASA cFS Pickle pickle.load deserializationEPSS 0.4%CVE-2025-30480MEDIUMDell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerProtect Data Manager.EPSS 0.4%CVE-2026-20643MEDIUMA cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security ImprovemEPSS 0.4%CVE-2022-29191MEDIUMMissing validation causes denial of service via `GetSessionTensor` in TensorFlowEPSS 0.4%CVE-2026-3230LOWImproper key_share validation in TLS 1.3 HelloRetryRequestEPSS 0.4%CVE-2023-48634HIGHZDI-CAN-22175: Adobe After Effects AEP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-34098HIGHZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 1 of 2EPSS 0.4%CVE-2026-53492HIGHcontainerd CRI checkpoint restore CDI annotation smugglingEPSS 0.4%CVE-2017-6795—A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an aEPSS 0.4%