Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2021-0072MEDIUMImproper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in WinEPSS 0.3%CVE-2025-15035MEDIUMArbitrary File Deletion Vulnerability in TP-Link Archer AXE75EPSS 0.3%CVE-2026-9969HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary EPSS 0.3%CVE-2026-18211MEDIUMKeycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domainsEPSS 0.3%CVE-2025-71417HIGHPocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponsePacketEPSS 0.3%CVE-2026-33729MEDIUMOpenFGA has an Authorization Bypass through cached keysEPSS 0.3%CVE-2026-16378HIGHOther issue in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.3%CVE-2026-33589HIGHArbitrary File Read via Local File Inclusion (LFI)EPSS 0.3%CVE-2024-52592MEDIUMMissing validation allows spoofed poll updates in MisskeyEPSS 0.3%CVE-2025-67493HIGHHomarr: missing input sanitization and possible privilege escalation through ldap search query injectionEPSS 0.3%CVE-2025-66400MEDIUMmdast-util-to-hast unsanitized class attributeEPSS 0.3%CVE-2026-22700HIGHRustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKEEPSS 0.3%CVE-2026-32629MEDIUMphpMyFAQ: Stored XSS via Unsanitized Email Field in Admin FAQ EditorEPSS 0.3%CVE-2023-28981MEDIUMJunos OS and Junos OS Evolved: If malformed IPv6 router advertisements are received, memory corruption will occur which causes an rpd crashEPSS 0.3%CVE-2026-10917HIGHInsufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2026-44518MEDIUMliboqs: XMSS Buffer Overread BugEPSS 0.3%CVE-2025-1080HIGHMacro URL arbitrary script executionEPSS 0.3%CVE-2025-59187HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-10911HIGHInsufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2026-10920HIGHInsufficient validation of untrusted input in WebShare in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compEPSS 0.3%