Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2021-1454MEDIUMCisco IOS XE SD-WAN Software Parameter Injection VulnerabilitiesEPSS 0.3%CVE-2026-11086HIGHInappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer procEPSS 0.3%CVE-2026-11022MEDIUMInsufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromisedEPSS 0.3%CVE-2024-33624MEDIUMImproper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an unauthenticated userEPSS 0.3%CVE-2026-14382CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially performEPSS 0.3%CVE-2024-45601HIGHLocal file Inclusion via static file serving functionality in MesopEPSS 0.3%CVE-2026-11016MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised EPSS 0.3%CVE-2021-3843MEDIUMA potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated EPSS 0.3%CVE-2026-63206MEDIUMZammad: Remote image tracking bypass via shortened URL schemeEPSS 0.3%CVE-2026-23887MEDIUMGroup-Office has stored XSS vulnerability via unsanitized filenamesEPSS 0.3%CVE-2025-3885MEDIUMHarman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service VulnerabilityEPSS 0.3%CVE-2025-24255HIGHA file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VentEPSS 0.3%CVE-2026-96760CRITICALAuthlib library contains a signature‑verification bypass vulnerabilityEPSS 0.3%CVE-2025-57835HIGHAn issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2023-43758HIGHImproper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privEPSS 0.3%CVE-2025-7674HIGHnavify Monitoring API input validationEPSS 0.3%CVE-2022-48321MEDIUMSSRF in agent-receiver APIEPSS 0.3%CVE-2026-84462HIGHZammad: AI Agent template sanitizer bypass leads to remote code executionEPSS 0.3%CVE-2024-23294HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to cEPSS 0.3%CVE-2026-11095CRITICALInsufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.3%