Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-48998MEDIUMguzzlehttp/psr7 has Host Confusion via Authority ReinterpretationEPSS 0.3%CVE-2024-23705CRITICALIn multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could leadEPSS 0.3%CVE-2025-61614HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2023-0775MEDIUMBluetooth LE Invalid prepare write request command leads to denial of serviceEPSS 0.3%CVE-2026-5915HIGHInsufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bEPSS 0.3%CVE-2025-61616HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2020-3201MEDIUMCisco IOS and IOS XE Software Tcl Denial of Service VulnerabilityEPSS 0.3%CVE-2025-61615HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61613HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61612HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2026-44337MEDIUMPraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queriesEPSS 0.3%CVE-2025-66866MEDIUMAn issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafEPSS 0.3%CVE-2026-11460MEDIUMBoost Serialization improper validation of specified type of inputEPSS 0.3%CVE-2021-0168MEDIUMImproper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in WinEPSS 0.3%CVE-2024-41565MEDIUMJustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. TEPSS 0.3%CVE-2025-44526MEDIUMRealtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low EPSS 0.3%CVE-2026-21683HIGHiccDEV has Type Confusion in icStatusCMM::CIccEvalCompare::EvaluateProfile()EPSS 0.3%CVE-2026-6790MEDIUMIn Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what pEPSS 0.3%CVE-2024-12355MEDIUMSourceCodester Phone Contact Manager System ContactBook.cpp adding input validationEPSS 0.3%CVE-2026-13851CRITICALInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to EPSS 0.3%