Fallos del tipo CWE-20

5454 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-8007HIGHInsufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised theEPSS 0.3%CVE-2026-13834HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2023-33099HIGHImproper Input Validation in Multi-Mode Call ProcessorEPSS 0.3%CVE-2023-33103HIGHImproper Input Validation in Multi-Mode Call ProcessorEPSS 0.3%CVE-2025-59886HIGHImproper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access tEPSS 0.3%CVE-2026-13829HIGHInsufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had EPSS 0.3%CVE-2026-14428HIGHInsufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compEPSS 0.3%CVE-2026-17663HIGHInsufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had comprEPSS 0.3%CVE-2026-9914HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2023-33057HIGHImproper Input Validation in Multi-Mode Call ProcessorEPSS 0.3%CVE-2026-10971HIGHInsufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had EPSS 0.3%CVE-2023-33100HIGHImproper input validation in Multi-Mode Call ProcessorEPSS 0.3%CVE-2023-33104HIGHImproper input Validation in Multi-Mode Call ProcessorEPSS 0.3%CVE-2026-9898HIGHInsufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compEPSS 0.3%CVE-2022-21180MEDIUMImproper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local acEPSS 0.3%CVE-2026-14401HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had comEPSS 0.3%CVE-2026-7967HIGHInsufficient validation of untrusted input in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromisEPSS 0.3%CVE-2026-15149MEDIUMWP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price ManipulationEPSS 0.3%CVE-2025-24299HIGHImproper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an esEPSS 0.3%CVE-2026-9885HIGHInsufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromisEPSS 0.3%