Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-13851CRITICALInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to EPSS 0.3%CVE-2023-32641HIGHImproper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of sEPSS 0.3%CVE-2026-29137MEDIUMLong Subject UntaggingEPSS 0.3%CVE-2026-49214MEDIUMguzzlehttp/psr7 has CRLF Injection via URI Host ComponentEPSS 0.3%CVE-2026-86475MEDIUMAppointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appointment SubmissionEPSS 0.3%CVE-2023-24463MEDIUMImproper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to poEPSS 0.3%CVE-2026-23839CRITICALMovary vulnerable to Cross-site Scripting with `?categoryUpdated=` paramEPSS 0.3%CVE-2026-13852CRITICALInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to EPSS 0.3%CVE-2026-100647MEDIUMvLLM before 0.29.0 CPU Exhaustion via unbounded cache_saltEPSS 0.3%CVE-2024-28028HIGHImproper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially eEPSS 0.3%CVE-2026-18504MEDIUMfastify vulnerable to schema validation bypass via root primitive coercion mismatchEPSS 0.3%CVE-2024-41945LOWThe fuels-ts typescript SDK has no awareness of to-be-spent transactionsEPSS 0.3%CVE-2026-10992MEDIUMInsufficient data validation in Animation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive EPSS 0.3%CVE-2026-34762LOWElla Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriberEPSS 0.3%CVE-2026-11013MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised EPSS 0.3%CVE-2026-11008MEDIUMInsufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had comprEPSS 0.3%CVE-2024-4175MEDIUMImproper Input Validation vulnerability in Hyperion Web ServerEPSS 0.3%CVE-2026-11007MEDIUMInsufficient validation of untrusted input in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had cEPSS 0.3%CVE-2026-10968HIGHInsufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compEPSS 0.3%CVE-2025-15035MEDIUMArbitrary File Deletion Vulnerability in TP-Link Archer AXE75EPSS 0.3%