Fallos del tipo CWE-20

5454 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-21588HIGHAdobe InDesign Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-22228HIGHAdobe Bridge Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-21574HIGHAdobe Photoshop Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-26388HIGHZDI-CAN-20286: Adobe Substance 3D Stager USDZ File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-1514MEDIUMCisco SD-WAN Software Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-11021CRITICALInsufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had comprEPSS 0.3%CVE-2026-10983CRITICALInsufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform EPSS 0.3%CVE-2026-10974CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially performEPSS 0.3%CVE-2026-15149MEDIUMWP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price ManipulationEPSS 0.3%CVE-2023-33099HIGHImproper Input Validation in Multi-Mode Call ProcessorEPSS 0.3%CVE-2026-9885HIGHInsufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromisEPSS 0.3%CVE-2026-14429HIGHInsufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised theEPSS 0.3%CVE-2020-1682MEDIUMJunos OS: SRX1500, vSRX, SRX4K, NFX150, NFX250: Denial of service vulnerability executing local CLI commandEPSS 0.3%CVE-2026-14412HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2023-33103HIGHImproper Input Validation in Multi-Mode Call ProcessorEPSS 0.3%CVE-2026-19177HIGHInsufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the EPSS 0.3%CVE-2026-17660HIGHInsufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised EPSS 0.3%CVE-2026-7967HIGHInsufficient validation of untrusted input in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromisEPSS 0.3%CVE-2025-59886HIGHImproper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access tEPSS 0.3%CVE-2025-24299HIGHImproper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an esEPSS 0.3%