Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2025-40556HIGHA vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet ATEC 550-445 (All versEPSS 0.2%CVE-2021-26327—Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.EPSS 0.2%CVE-2023-34431HIGHImproper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilEPSS 0.2%CVE-2026-79260MEDIUMImproper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2026-16316LOWMalformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuardEPSS 0.2%CVE-2026-75633MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.2%CVE-2024-54011MEDIUMMissing Error/Exception HandlingEPSS 0.2%CVE-2026-87472MEDIUMImproper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2026-15316HIGHDenial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200EPSS 0.2%CVE-2024-31965MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.2%CVE-2025-66614HIGHApache Tomcat: Client certificate verification bypass due to virtual host mappingEPSS 0.2%CVE-2026-17747MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had EPSS 0.2%CVE-2024-9875HIGHOkta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo commEPSS 0.2%CVE-2026-8536LOWInsufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had EPSS 0.2%CVE-2025-31259HIGHA privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS EPSS 0.2%CVE-2023-48368MEDIUMImproper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of servicEPSS 0.2%CVE-2026-7360LOWInsufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had comproEPSS 0.2%CVE-2022-24417HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%CVE-2026-79253MEDIUMImproper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social enginEPSS 0.2%CVE-2022-24418HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%