Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-11113CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2024-25008MEDIUMEricsson RAN Compute and Site Controller 6610 - Improper Input Validation VulnerabilityEPSS 0.3%CVE-2026-16641CRITICALCommerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084EPSS 0.3%CVE-2026-85528MEDIUMSnowflake JDBC Driver auto-configuration account validation permits credential redirectionEPSS 0.3%CVE-2021-3599MEDIUMA potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local EPSS 0.3%CVE-2026-14122HIGHInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker toEPSS 0.3%CVE-2025-24501MEDIUMAn improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.EPSS 0.3%CVE-2026-0419MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150EPSS 0.3%CVE-2025-12842MEDIUMBooking Plugin for WordPress Appointments – Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email SendingEPSS 0.3%CVE-2026-23840CRITICALMovary vulnerable to Cross-site Scripting with `?categoryDeleted=` paramEPSS 0.3%CVE-2026-92581MEDIUMAVideo through 29.0 Like Counter Desynchronization via Array ParameterEPSS 0.3%CVE-2021-38122MEDIUMCross-Site Scripting (XSS) in Advance AuthenticationEPSS 0.3%CVE-2026-17831MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromiseEPSS 0.3%CVE-2025-15246MEDIUMaizuda snail-job API FurySerializer.deserialize deserializationEPSS 0.3%CVE-2026-3096MEDIUMReverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential TheftEPSS 0.3%CVE-2024-5439MEDIUMBlocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-33284LOWGlobalLeaks has insufficient URL validation in user support APIEPSS 0.3%CVE-2026-17791MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisedEPSS 0.3%CVE-2025-58175MEDIUMGeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity ResolutionEPSS 0.3%CVE-2022-30711HIGHImproper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.EPSS 0.3%