Fallos del tipo CWE-20

5454 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-32480MEDIUM Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerabilEPSS 0.3%CVE-2026-14723MEDIUMAD-Security AD_Miner Cache analyse_cache.py request_a deserializationEPSS 0.3%CVE-2025-15117LOWDromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserializationEPSS 0.3%CVE-2026-0403LOWInsufficient input validation in NETGEAR Orbi routersEPSS 0.3%CVE-2025-15358HIGHDVP-12SE11T - Denial of Service VulnerabilityEPSS 0.3%CVE-2023-41781MEDIUMXSS Vulnerability in ZTE MF258 ProductsEPSS 0.3%CVE-2026-15531MEDIUMyashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserializationEPSS 0.3%CVE-2020-1619MEDIUMJunos OS: QFX10K Series, EX9200 Series, MX Series, PTX Series: Privilege escalation vulnerability in NG-RE.EPSS 0.3%CVE-2026-56333MEDIUMCapgo - Server-Side Validation Bypass via Direct Browser-Side Organization Security Settings UpdatesEPSS 0.3%CVE-2023-42981MEDIUMProcessing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was adEPSS 0.3%CVE-2026-18174MEDIUM@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-ForEPSS 0.3%CVE-2018-10497—This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. AnEPSS 0.3%CVE-2023-25859HIGHAdobe Illustrator Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-44183MEDIUMJunos OS: QFX5000 Series, EX4600 Series: In a VxLAN scenario an adjacent attacker within the VxLAN sending genuine packets may cause a DMA memory leak to occur.EPSS 0.3%CVE-2025-57805HIGHThe Scratch Channel's Publish Articles POST Request Can Upload Articles Without ValidationEPSS 0.3%CVE-2025-5174MEDIUMerdogant pypickle pypickle.py load deserializationEPSS 0.3%CVE-2025-47182MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2021-20268—An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF scrEPSS 0.3%CVE-2021-0066HIGHImproper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 anEPSS 0.3%CVE-2018-10499—This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.EPSS 0.3%