Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-13813HIGHInsufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromisEPSS 0.3%CVE-2024-51741MEDIUMRedis allows denial-of-service due to malformed ACL selectorsEPSS 0.3%CVE-2024-4353MEDIUMStored XSS in Generate Board Name Input FieldEPSS 0.3%CVE-2026-13856HIGHInsufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had coEPSS 0.3%CVE-2026-7345HIGHInsufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromiseEPSS 0.3%CVE-2025-44016HIGHFile Hash Validation Bypass in NomadBranch.exeEPSS 0.3%CVE-2021-0156HIGHImproper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation oEPSS 0.3%CVE-2026-11047CRITICALInappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the reEPSS 0.3%CVE-2026-75991HIGHIllustrator | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2026-100663HIGHNetty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3EPSS 0.3%CVE-2024-4028LOWKeycloak-core: stored xss in keycloak when creating a items in admin consoleEPSS 0.3%CVE-2026-7905HIGHInsufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had comEPSS 0.3%CVE-2026-7916HIGHInsufficient data validation in InterestGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renEPSS 0.3%CVE-2026-23489CRITICALFields GLPI plugin vulnerable to RCE in dropdown generationEPSS 0.3%CVE-2026-10966CRITICALInappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox esEPSS 0.3%CVE-2025-7062MEDIUMStored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi EducationEPSS 0.3%CVE-2023-22329LOWImproper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of EPSS 0.3%CVE-2024-52337MEDIUMTuned: improper sanitization of `instance_name` parameter of the `instance_create()` methodEPSS 0.3%CVE-2026-42389MEDIUMReject more queries with invalid header valuesEPSS 0.3%CVE-2024-24984MEDIUMImproper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated useEPSS 0.3%