Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-78943LOWImproper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer procEPSS 0.3%CVE-2026-7998MEDIUMInsufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2025-21126MEDIUMInDesign Desktop | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2023-52368MEDIUMInput verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormallEPSS 0.3%CVE-2026-16415MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the conEPSS 0.3%CVE-2024-21452HIGHImproper Input Validation in Automotive TelematicsEPSS 0.3%CVE-2025-46340HIGHMisskey CSS Style Injection Vulnerability In `MkUrlPreview`EPSS 0.3%CVE-2024-28127HIGHImproper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privEPSS 0.3%CVE-2026-30963LOWCapsule Namespace Hijacking via subresourceEPSS 0.3%CVE-2024-29214HIGHImproper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enaEPSS 0.3%CVE-2023-34440HIGHImproper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privEPSS 0.3%CVE-2024-24582HIGHImproper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable eEPSS 0.3%CVE-2026-67326HIGHGitPython before 3.1.50 Newline Injection via config_writer sectionEPSS 0.3%CVE-2025-61583MEDIUMTS3 Manager is vulnerable to unauthenticated reflected XSS attack due to insecure error handlingEPSS 0.3%CVE-2026-0051MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This EPSS 0.3%CVE-2024-23790LOWMissing file type check in avatar picture uploadEPSS 0.3%CVE-2025-13826HIGHIncorrect input validation on the Zervit portable HTTP/Web serverEPSS 0.3%CVE-2024-3938MEDIUMThe "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it caEPSS 0.3%CVE-2021-35531—Remote Code Execution in TXpert Hub CoreTec 4EPSS 0.3%CVE-2025-41257MEDIUMSuprema BioStar 2 Insecure Password ChangeEPSS 0.3%