Fallos del tipo CWE-20

5453 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-44811HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-55630LOWDOM Clobbering leads to temporary DOS in the note viewer in JoplinEPSS 0.3%CVE-2023-43037MEDIUMIBM Maximo Application Suite improper access controlEPSS 0.3%CVE-2023-25865HIGHAdobe Substance 3D Stager OBJ File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-39410MEDIUMHono has a non-breaking space prefix bypass in cookie name handling in getCookie()EPSS 0.3%CVE-2025-26489MEDIUMImproper input validation in Netconf service in Infinera MTC-9EPSS 0.3%CVE-2023-25867HIGHAdobe Substance 3D Stager PCX File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-18217LOWKeycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollutionEPSS 0.3%CVE-2026-76323MEDIUMSPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk EnterpriseEPSS 0.3%CVE-2026-45615HIGHmouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OER PayloadEPSS 0.3%CVE-2026-55256MEDIUMIn parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead toEPSS 0.3%CVE-2025-3837MEDIUMImproper Input Validation vulnerability in the End of Life (EOL) OVA based connect componentEPSS 0.3%CVE-2025-29646HIGHAn issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentReEPSS 0.3%CVE-2026-4451HIGHInsufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromiEPSS 0.3%CVE-2025-11273MEDIUMLaChatterie Verger provider.ts redirectToAuthorization deserializationEPSS 0.3%CVE-2022-34345—Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentiallyEPSS 0.3%CVE-2026-3545CRITICALInsufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbEPSS 0.3%CVE-2026-100664HIGHNetty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority ConfusionEPSS 0.3%CVE-2026-13806HIGHInsufficient validation of untrusted input in Accessibility in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had comproEPSS 0.3%CVE-2026-19153HIGHInsufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromisedEPSS 0.3%