Fallos del tipo CWE-20

5454 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2018-10499—This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.EPSS 0.3%CVE-2023-3456—Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service cEPSS 0.3%CVE-2022-29195MEDIUMMissing validation causes denial of service in TensorFlow via `StagePeek`EPSS 0.3%CVE-2022-29199MEDIUMMissing validation causes denial of service in TensorFlow via `LoadAndRemapMatrix`EPSS 0.3%CVE-2026-54663MEDIUMswagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`EPSS 0.3%CVE-2022-29207MEDIUMUndefined behavior when users supply invalid resource handles in TensorFlowEPSS 0.3%CVE-2026-21712MEDIUMA flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalizedEPSS 0.3%CVE-2026-34442MEDIUMFreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutEPSS 0.3%CVE-2024-1534MEDIUMBooster for WooCommerce <= 7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortocdeEPSS 0.3%CVE-2022-29200MEDIUMMissing validation causes denial of service in TensorFlow via `LSTMBlockCell`EPSS 0.3%CVE-2022-29196MEDIUMMissing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2`EPSS 0.3%CVE-2022-29193MEDIUMMissing validation causes `TensorSummaryV2` in TensorFlow to crashEPSS 0.3%CVE-2022-29197MEDIUMMissing validation causes denial of service in TensorFlow via `UnsortedSegmentJoin`EPSS 0.3%CVE-2022-29198MEDIUMMissing validation causes denial of service in TensorFlow via `SparseTensorToCSRSparseMatrix`EPSS 0.3%CVE-2021-1233MEDIUMCisco SD-WAN Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-2751MEDIUMExclusive Addons for Elementor <= 2.6.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via InfoBoxEPSS 0.3%CVE-2026-13780CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2026-17848CRITICALInteger overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a cEPSS 0.3%CVE-2026-17803CRITICALInsufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comproEPSS 0.3%CVE-2026-14056CRITICALInsufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised thEPSS 0.3%