Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2025-61084HIGHMDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. EPSS 0.2%CVE-2021-25509MEDIUMA missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the WiEPSS 0.2%CVE-2025-69278HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2022-1242HIGHApport can be tricked into connecting to arbitrary sockets as the root userEPSS 0.2%CVE-2025-69279HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2023-25951MEDIUMImproper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileEPSS 0.2%CVE-2024-28977LOWDell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local attacker with low prEPSS 0.2%CVE-2026-42301HIGHImproper Input Validation leading to Improper Control of Generation of Code ('Code Injection') in pyp2specEPSS 0.2%CVE-2026-6777MEDIUMOther issue in the Networking: DNS componentEPSS 0.2%CVE-2026-12025MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromisedEPSS 0.2%CVE-2022-33945HIGHImproper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially EPSS 0.2%CVE-2024-10846MEDIUMExcessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loopEPSS 0.2%CVE-2026-17939MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spooEPSS 0.2%CVE-2026-7931MEDIUMInsufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker to perform UI spoEPSS 0.2%CVE-2022-36853LOWIntent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.EPSS 0.2%CVE-2026-18009MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spooEPSS 0.2%CVE-2023-21473MEDIUMImproper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitraryEPSS 0.2%CVE-2023-21472MEDIUMImproper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitraryEPSS 0.2%CVE-2022-36873MEDIUMImproper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC addressEPSS 0.2%CVE-2026-100833HIGHContrast before 1.23.1 Image Substitution via Policy GenerationEPSS 0.2%