Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-43570MEDIUM A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permEPSS 0.2%CVE-2026-11676HIGHInsufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker EPSS 0.2%CVE-2026-103237HIGHMISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant RowsEPSS 0.2%CVE-2026-9214MEDIUMInsufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.EPSS 0.2%CVE-2024-5913MEDIUMPAN-OS: Improper Input Validation Vulnerability in PAN-OSEPSS 0.2%CVE-2024-34545MEDIUMImproper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable infoEPSS 0.2%CVE-2022-35893HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxeEPSS 0.2%CVE-2026-11140MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process EPSS 0.2%CVE-2026-11128MEDIUMInappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage iEPSS 0.2%CVE-2026-12016HIGHInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rendererEPSS 0.2%CVE-2026-11093MEDIUMInappropriate implementation in Printing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2026-0417MEDIUMInsufficient input validation in certain NETGEAR routersEPSS 0.2%CVE-2026-21272HIGHDreamweaver Desktop | Improper Input Validation (CWE-20)EPSS 0.2%CVE-2022-31808HIGHA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V2.85.44), SiPass integrated ACC-AP (All versions <EPSS 0.2%CVE-2026-0415MEDIUMInsufficient input validation vulnerability in certain Orbi routersEPSS 0.2%CVE-2026-101041MEDIUMVulnerability-Lookup - Race Condition in Account Recovery Token Consumption Allows Password TakeoverEPSS 0.2%CVE-2025-7375MEDIUMUnauthenticated Denial-of-Service Vulnerability in Omada EAP610EPSS 0.2%CVE-2019-1729MEDIUMCisco NX-OS Software Arbitrary File Overwrite VulnerabilityEPSS 0.2%CVE-2021-33142MEDIUMImproper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privilEPSS 0.2%CVE-2025-5173MEDIUMHumanSignal label-studio-ml-backend PT File neural_nets.py load deserializationEPSS 0.2%