Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-28193MEDIUMNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted daEPSS 0.3%CVE-2026-17909MEDIUMInsufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crEPSS 0.3%CVE-2026-34773MEDIUMElectron: Registry key path injection in app.setAsDefaultProtocolClient on WindowsEPSS 0.3%CVE-2023-5275LOWImproper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-service (DoS) condition EPSS 0.3%CVE-2019-15273MEDIUMCisco TelePresence Collaboration Endpoint Software Arbitrary File Overwrite VulnerabilitiesEPSS 0.3%CVE-2021-0159HIGHImproper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enabEPSS 0.3%CVE-2022-21136MEDIUMImproper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via localEPSS 0.3%CVE-2026-71390MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2022-28186MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the EPSS 0.3%CVE-2026-17698HIGHInsufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-oEPSS 0.3%CVE-2022-28188MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the EPSS 0.3%CVE-2026-70589MEDIUMGhost: Archived Offers can be RedeemedEPSS 0.3%CVE-2021-0154HIGHImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation ofEPSS 0.3%CVE-2026-23880HIGHOnboardLite has stored Cross-site Scripting issue that may lead to admin Account Take OverEPSS 0.3%CVE-2026-51598MEDIUMAn input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticateEPSS 0.3%CVE-2026-11738MEDIUMInsufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.EPSS 0.3%CVE-2026-33797HIGHJunos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP resetEPSS 0.3%CVE-2022-21933MEDIUMASUS VivoMini/Mini PC - improper input validationEPSS 0.3%CVE-2022-1107MEDIUMDuring an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovereEPSS 0.3%CVE-2020-12487HIGHCommand Execution Vulnerability in ABE serviceEPSS 0.3%