Fallos del tipo CWE-20

5454 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-22046HIGHiccDEV has heap-buffer-overflow in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cppEPSS 0.3%CVE-2025-3070MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilEPSS 0.3%CVE-2026-13806HIGHInsufficient validation of untrusted input in Accessibility in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had comproEPSS 0.3%CVE-2026-19153HIGHInsufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromisedEPSS 0.3%CVE-2026-17686HIGHInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromiseEPSS 0.3%CVE-2025-13428HIGHRCE in SecOps SOAR server via user-provided Python packagesEPSS 0.3%CVE-2021-4041—A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lEPSS 0.3%CVE-2024-20318HIGHA vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the linEPSS 0.3%CVE-2026-10980MEDIUMInsufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromisedEPSS 0.3%CVE-2025-0052HIGHFlashBlade DOS VulnerabilityEPSS 0.3%CVE-2022-29194MEDIUMMissing validation causes denial of service via `DeleteSessionTensor` in TensorFlowEPSS 0.3%CVE-2026-20237CRITICALCisco Identity Services Engine Hardening Release - Input Validation VulnerabilitiesEPSS 0.3%CVE-2025-63397MEDIUMImproper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code dEPSS 0.3%CVE-2026-14038CRITICALInsufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromEPSS 0.3%CVE-2023-22228HIGHAdobe Bridge Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-0514HIGHExecutable hyperlink Windows path targets executed unconditionally on activationEPSS 0.3%CVE-2023-26388HIGHZDI-CAN-20286: Adobe Substance 3D Stager USDZ File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-21621HIGHAdobe FrameMaker Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-35896MEDIUMAn issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An attacker can EPSS 0.3%CVE-2025-4762LOWInsecure Direct Object Reference (IDOR) vulnerability in eSignaViewerEPSS 0.3%