Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-47924MEDIUMArbitrary Code Execution using the validate function of csaf-validator-libEPSS 0.3%CVE-2021-4211MEDIUMA potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdEPSS 0.3%CVE-2020-1986MEDIUMSecdo: Local authenticated users can cause Windows system crashEPSS 0.3%CVE-2024-36284MEDIUMImproper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enaEPSS 0.3%CVE-2021-4212MEDIUMA potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacEPSS 0.3%CVE-2025-14606LOWtiny-rdm Tiny RDM Pickle Decoding pickle_convert.go pickle.loads deserializationEPSS 0.3%CVE-2021-25401—Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.EPSS 0.3%CVE-2024-7980HIGHInsufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege eEPSS 0.3%CVE-2021-34752MEDIUMCisco Firepower Threat Defense Command Injection VulnerabilitiesEPSS 0.3%CVE-2026-8013MEDIUMInsufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin dEPSS 0.3%CVE-2026-14045MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised EPSS 0.3%CVE-2026-8538MEDIUMInsufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised theEPSS 0.3%CVE-2026-17706MEDIUMInsufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had comEPSS 0.3%CVE-2026-17769MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2026-14116MEDIUMInsufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a useEPSS 0.3%CVE-2026-23841CRITICALMovary vulnerable to Cross-site Scripting with `?categoryCreated=` paramEPSS 0.3%CVE-2026-17773MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2024-26002HIGHPHOENIX CONTACT: File ownership manipulation in CHARX SeriesEPSS 0.3%CVE-2026-17767MEDIUMInsufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had cEPSS 0.3%CVE-2026-86351MEDIUMMISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URLEPSS 0.3%