Fallos del tipo CWE-20

5454 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-79288MEDIUMImproper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inEPSS 0.3%CVE-2026-17679MEDIUMInsufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comproEPSS 0.3%CVE-2026-14021MEDIUMInsufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2022-27835HIGHImproper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.EPSS 0.3%CVE-2025-0660MEDIUMStored XSS in Folder Function by Rogue AdminEPSS 0.3%CVE-2026-13816MEDIUMInsufficient validation of untrusted input in File Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leaEPSS 0.3%CVE-2022-39259LOWJadx-gui subject to Denial of Service via Swing HTML renderingEPSS 0.3%CVE-2026-17735HIGHInsufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised EPSS 0.3%CVE-2026-14022MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised EPSS 0.3%CVE-2023-7248MEDIUMOpenText Vertica Management console might be prone to bypass via crafted requestsEPSS 0.3%CVE-2025-8571MEDIUMConcrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard PageEPSS 0.3%CVE-2025-10061MEDIUMMalformed $group Query May Cause MongoDB Server to CrashEPSS 0.3%CVE-2024-0045HIGHIn smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proxiEPSS 0.3%CVE-2026-33588HIGHArbitrary File Write Through Path TraversalEPSS 0.3%CVE-2022-2868—libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacEPSS 0.3%CVE-2026-18206LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching bypassEPSS 0.3%CVE-2026-6231MEDIUMbson_validate may skip validation when processing certain inputsEPSS 0.3%CVE-2026-79013MEDIUMImproper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafEPSS 0.3%CVE-2026-20715HIGHImproper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard ManageabEPSS 0.3%CVE-2022-29211MEDIUMSegfault in TensorFlow if `tf.histogram_fixed_width` is called with NaN valuesEPSS 0.3%