Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2019-1588MEDIUMCisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Arbitrary File Read VulnerabilityEPSS 0.3%CVE-2025-23336MEDIUMNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of service by loading aEPSS 0.3%CVE-2025-70123HIGHAn improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. TEPSS 0.3%CVE-2026-13057MEDIUMAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_METAEPSS 0.3%CVE-2021-21557HIGHDell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user wEPSS 0.3%CVE-2022-21212MEDIUMImproper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of EPSS 0.3%CVE-2018-0337—A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to executeEPSS 0.3%CVE-2023-25879HIGHZDI-CAN-19389: Adobe Dimension OBJ File Improper Input Validation Remote Code ExecutionEPSS 0.3%CVE-2026-17768CRITICALInsufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisEPSS 0.3%CVE-2026-13920CRITICALInsufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had comEPSS 0.3%CVE-2026-17991CRITICALInsufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rEPSS 0.3%CVE-2026-17672CRITICALInsufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisEPSS 0.3%CVE-2026-87083MEDIUMtile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserializationEPSS 0.3%CVE-2026-17738CRITICALInsufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisedEPSS 0.3%CVE-2026-18002CRITICALInsufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromiEPSS 0.3%CVE-2026-13817HIGHInsufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform EPSS 0.3%CVE-2026-14382CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially performEPSS 0.3%CVE-2026-14411CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially performEPSS 0.3%CVE-2026-17940CRITICALInsufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attackeEPSS 0.3%CVE-2026-17684CRITICALInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who haEPSS 0.3%