Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-14412HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2022-24925MEDIUMImproper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denialEPSS 0.3%CVE-2026-15757MEDIUMInsufficient input validation vulnerability in NETGEAR DGND3700v1 modem routerEPSS 0.3%CVE-2026-29791MEDIUMAgentgateway: Missing parameter sanitization in MCP to OpenAPI conversionEPSS 0.3%CVE-2026-9914HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2026-14429HIGHInsufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised theEPSS 0.3%CVE-2026-86885MEDIUMAn input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An attacker in radio raEPSS 0.3%CVE-2025-12944MEDIUMImproper input validation in NETGEAR DGN2200v4EPSS 0.3%CVE-2025-7507MEDIUMelink – Embed Content <= 1.1.0 - Authenticated (Contributor+) Insufficient Input ValidationEPSS 0.3%CVE-2024-28047MEDIUMImproper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information discloEPSS 0.3%CVE-2021-36283HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%CVE-2023-26293HIGHA vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation PEPSS 0.2%CVE-2025-6703LOWtransport/fc.rs: panic attempting to send MAX_DATA with value larger max varintEPSS 0.2%CVE-2026-53513CRITICALBetter Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationEPSS 0.2%CVE-2025-8007HIGHRockwell Automation 1756-ENT2R, EN4TR, EN4TRXT VulnerabilityEPSS 0.2%CVE-2024-27805MEDIUMAn issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and EPSS 0.2%CVE-2025-40935MEDIUMA vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUEPSS 0.2%CVE-2026-17690MEDIUMInsufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-EPSS 0.2%CVE-2020-12961—A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the EPSS 0.2%CVE-2024-25743HIGHIn the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGEPSS 0.2%