Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-87573MEDIUMImproper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a craEPSS 0.3%CVE-2026-34668MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2026-14411CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially performEPSS 0.3%CVE-2022-26864MEDIUMPrior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vuEPSS 0.3%CVE-2022-26862MEDIUMPrior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vuEPSS 0.3%CVE-2021-0176MEDIUMImproper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in WinEPSS 0.3%CVE-2026-1782MEDIUMMetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'EPSS 0.3%CVE-2025-63785MEDIUMA DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerabilEPSS 0.3%CVE-2022-26863MEDIUMPrior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vuEPSS 0.3%CVE-2024-21976HIGHImproper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary cEPSS 0.3%CVE-2026-101266LOWCheckout validation bypassEPSS 0.3%CVE-2025-67170MEDIUMA reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user'sEPSS 0.3%CVE-2022-28190MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where imprEPSS 0.3%CVE-2025-48985LOWA vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypEPSS 0.3%CVE-2026-82441CRITICALApache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency KeysEPSS 0.3%CVE-2026-79251MEDIUMImproper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin poliEPSS 0.3%CVE-2026-11120CRITICALInsufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who hadEPSS 0.3%CVE-2026-11255HIGHInsufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had cEPSS 0.3%CVE-2021-0076MEDIUMImproper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operatiEPSS 0.3%CVE-2026-13917MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who coEPSS 0.3%