Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-36853LOWIntent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.EPSS 0.2%CVE-2023-42012MEDIUMIBM UrbanCode Deploy denial of serviceEPSS 0.2%CVE-2026-14137MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who coEPSS 0.2%CVE-2025-6377HIGHArena® Simulation Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-32070MEDIUMXSSes in AJAXPollEPSS 0.2%CVE-2026-11023MEDIUMInappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renEPSS 0.2%CVE-2026-79259MEDIUMImproper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictEPSS 0.2%CVE-2025-43348MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. AnEPSS 0.2%CVE-2026-59298LOWPotential for improper filtering of HTTP headers in Spring Cloud FunctionEPSS 0.2%CVE-2025-32073MEDIUMSystem message XSS in HTMLTagsEPSS 0.2%CVE-2025-6376HIGHArena® Simulation Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-13024MEDIUMInsufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromiEPSS 0.2%CVE-2025-32071MEDIUMWikibase CommonsInlineImageFormatter: i18n XSSEPSS 0.2%CVE-2026-10863MEDIUMMISP User-controlled order parameter in correlations over-correlation endpointEPSS 0.2%CVE-2026-11658MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromiEPSS 0.2%CVE-2026-11653MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderEPSS 0.2%CVE-2025-32069MEDIUMWikitext stored XSS on filepages due to dangerous WBMI serializationEPSS 0.2%CVE-2025-32067MEDIUMi18n XSS vulnerability in message growthexperimentsEPSS 0.2%CVE-2026-6328HIGHXQUIC Improper STREAM Frame Validation in Initial/Handshake PacketsEPSS 0.2%CVE-2024-37365HIGHFactoryTalk View ME Remote Code Execution Vulnerability via Project Save PathEPSS 0.2%