Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-11242HIGHInsufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised EPSS 0.3%CVE-2024-5533MEDIUMDivi <= 4.25.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-47909MEDIUMDreamweaver Desktop | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2021-3675MEDIUMsynaTEE.signed.dll Out-Of-Bounds Heap WriteEPSS 0.3%CVE-2026-17749CRITICALInsufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user toEPSS 0.3%CVE-2026-17786HIGHInsufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to iEPSS 0.3%CVE-2026-13480LOWOut-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handlerEPSS 0.3%CVE-2026-27299MEDIUMAdobe Framemaker | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2026-20020MEDIUMA vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjEPSS 0.3%CVE-2026-76198MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2022-22423MEDIUMIBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service EPSS 0.3%CVE-2026-48353MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2022-38076LOWImproper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially EPSS 0.3%CVE-2025-64176MEDIUMThinkDashboard: Arbitrary File Upload vulnerability in the Backup Import FeatureEPSS 0.3%CVE-2026-62519MEDIUMVulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that arEPSS 0.3%CVE-2025-64515MEDIUMOpen Forms prefill data in read-only components can be tamperedEPSS 0.3%CVE-2025-55006MEDIUMFrappe Learning Holds Potential for Malicious SVG Upload in Image Upload FeatureEPSS 0.3%CVE-2021-34752MEDIUMCisco Firepower Threat Defense Command Injection VulnerabilitiesEPSS 0.3%CVE-2024-36284MEDIUMImproper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enaEPSS 0.3%CVE-2025-15222LOWDromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserializationEPSS 0.3%