Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2017-6795—A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an aEPSS 0.4%CVE-2024-34098HIGHZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 1 of 2EPSS 0.4%CVE-2026-79376HIGHAn issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers tEPSS 0.4%CVE-2023-3770MEDIUMVulnerability in Ingeteam's INGEPAC DAEPSS 0.4%CVE-2023-44103—Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2026-26952MEDIUMPi-hole Web Interface has Stored HTML Injection via Local DNS Records (CNAME/Hosts) in data-tag AttributeEPSS 0.4%CVE-2025-57834HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380EPSS 0.4%CVE-2019-1959MEDIUMCisco Enterprise NFV Infrastructure Software Arbitrary File Read VulnerabilitiesEPSS 0.4%CVE-2026-20255MEDIUMImproper Input Validation through Classic Dashboards in Splunk EnterpriseEPSS 0.4%CVE-2019-1960MEDIUMCisco Enterprise NFV Infrastructure Software Arbitrary File Read VulnerabilitiesEPSS 0.4%CVE-2023-54393HIGHPocketMine-MP before 4.20.5 Denial of Service via LoginPacketEPSS 0.4%CVE-2023-3034MEDIUMReflected XSS in BKG Ntrip Professional Caster version <=2.0.44EPSS 0.4%CVE-2026-10938HIGHInappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proEPSS 0.4%CVE-2024-52590HIGHMissing validation allows spoofed profiles in MisskeyEPSS 0.4%CVE-2024-1638HIGHBluetooth characteristic LESC security requirement not enforced without additional flagsEPSS 0.4%CVE-2026-55306HIGHIn Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denial of service with EPSS 0.4%CVE-2026-73445MEDIUMSecurity Advisory 0167EPSS 0.4%CVE-2025-10630MEDIUMRegex DoS in Grafana Zabbix PluginEPSS 0.3%CVE-2024-5969MEDIUMAIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email SendingEPSS 0.3%CVE-2024-4787MEDIUMCost Calculator Builder PRO <= 3.1.75 - Unauthenticated Arbitrary Email SendingEPSS 0.3%