Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-33948LOWjq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed InputEPSS 0.3%CVE-2022-44611MEDIUMImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of EPSS 0.3%CVE-2022-29204MEDIUMMissing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2`EPSS 0.3%CVE-2024-5969MEDIUMAIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email SendingEPSS 0.3%CVE-2026-11914MEDIUMComposer - Critical - Unsupported - SA-CONTRIB-2026-046EPSS 0.3%CVE-2026-86768MEDIUMSnipe-IT before 8.7.0 Improper Input Validation via API CheckoutEPSS 0.3%CVE-2026-13924MEDIUMInsufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had cEPSS 0.3%CVE-2025-13909MEDIUMInformation Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII ExposureEPSS 0.3%CVE-2026-13921MEDIUMInsufficient validation of untrusted input in DeviceBoundSessionCredentials in Google Chrome prior to 150.0.7871.47 allowed a remote attackeEPSS 0.3%CVE-2026-76758MEDIUMLink content parser - Critical - Unsupported - SA-CONTRIB-2026-101EPSS 0.3%CVE-2026-14065MEDIUMInsufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromisedEPSS 0.3%CVE-2026-13926MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised EPSS 0.3%CVE-2026-14023MEDIUMInsufficient validation of untrusted input in SanitizerAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same EPSS 0.3%CVE-2026-29141HIGHBounded Subject Tag SanitizationEPSS 0.3%CVE-2026-29144HIGHUnicode Subject TagsEPSS 0.3%CVE-2026-53723MEDIUMguzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA TerminatorEPSS 0.3%CVE-2026-13791HIGHInsufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to EPSS 0.3%CVE-2026-9210MEDIUMCertain NETGEAR routers allow authenticated administrators to gain unintended control of the routerEPSS 0.3%CVE-2023-25881HIGHZDI-CAN-19390: Adobe Dimension OBJ File Improper Input Validation Remote Code ExecutionEPSS 0.3%CVE-2023-39137—An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.EPSS 0.3%