Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2025-59595HIGHCVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can seEPSS 0.3%CVE-2026-59650CRITICALMTI/A0 DH agreement exponentiates unvalidated peer valueEPSS 0.3%CVE-2026-56325LOWCapgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain LookupEPSS 0.3%CVE-2026-94092MEDIUMdmlc dgl utils.py _read_torch_data deserializationEPSS 0.3%CVE-2026-94091MEDIUMpiskvorky gensim Model Loader utils.py load deserializationEPSS 0.3%CVE-2020-3435MEDIUMCisco AnyConnect Secure Mobility Client for Windows Profile Modification VulnerabilityEPSS 0.3%CVE-2022-46701HIGHThe issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. ConnectEPSS 0.3%CVE-2024-20327HIGHA vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation ServicesEPSS 0.3%CVE-2025-66451MEDIUMLibreChat's Improper Input Validation in Prompt Creation API Enables Unauthorized Permission ChangesEPSS 0.3%CVE-2026-65891MEDIUMJoomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10EPSS 0.3%CVE-2026-34980MEDIUMOpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the networkEPSS 0.3%CVE-2025-52547HIGHDoS to the application servicesEPSS 0.3%CVE-2025-61768MEDIUMKuno CMS Vulnerable to Server-Side Request Forgery (SSRF) via Unsafe SVG UploadEPSS 0.3%CVE-2022-29201MEDIUMMissing validation in `QuantizedConv2D` results in undefined behavior in TensorFlowEPSS 0.3%CVE-2022-36448HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. There is an SMM memory corruption vulnerability in the Software SMIEPSS 0.3%CVE-2023-1789MEDIUMImproper Input Validation in firefly-iii/firefly-iiiEPSS 0.3%CVE-2023-46763—Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause backgEPSS 0.3%CVE-2022-44553MEDIUMThe HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. EPSS 0.3%CVE-2026-1577MEDIUMIBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueriesEPSS 0.3%CVE-2024-13798MEDIUMPost Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order CreationEPSS 0.3%