Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-13817HIGHInsufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform EPSS 0.3%CVE-2026-14078HIGHInsufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege EPSS 0.3%CVE-2026-17684CRITICALInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who haEPSS 0.3%CVE-2026-17671CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2026-47181HIGHPenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account TakeoverEPSS 0.3%CVE-2024-1244CRITICALRemote code execution and local privilege escalation due to UNC access and NetNTLMv2 hash theftEPSS 0.3%CVE-2024-1714HIGHAccess Request for Entitlement Values with Leading/Trailing WhitespaceEPSS 0.3%CVE-2026-6779MEDIUMOther issue in the JavaScript Engine componentEPSS 0.3%CVE-2025-40846HIGHHaloITSM open redirect via the returnUrlEPSS 0.3%CVE-2025-47096LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2020-35509MEDIUMA flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticatoEPSS 0.3%CVE-2023-42431LOWPotential XSS on user preferences pageEPSS 0.3%CVE-2026-65645MEDIUMRocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList anEPSS 0.3%CVE-2022-29192MEDIUMMissing validation crashes `QuantizeAndDequantizeV4Grad` in TensorFlowEPSS 0.3%CVE-2025-12285CRITICALMissing Initial Password ChangeEPSS 0.3%CVE-2026-63428MEDIUMHeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field setEPSS 0.3%CVE-2026-17795MEDIUMInappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendeEPSS 0.3%CVE-2026-22615MEDIUMDue to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privilEPSS 0.3%CVE-2023-25651MEDIUMSQL Injection Vulnerability in Some ZTE Mobile Internet ProductsEPSS 0.3%CVE-2026-24811CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inffast.cEPSS 0.3%