Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2025-43348MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. AnEPSS 0.2%CVE-2023-39538HIGHFailure when uploading a Logo image fileEPSS 0.2%CVE-2024-47238HIGHDell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attackEPSS 0.2%CVE-2025-14576HIGHPossible QML code injection in VectorImage componentEPSS 0.2%CVE-2024-28240HIGHGLPI-Agent's MSI package installation permits local users to change Agent configurationEPSS 0.2%CVE-2026-9986MEDIUMInsufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had cEPSS 0.2%CVE-2024-21944MEDIUMImproper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a sysEPSS 0.2%CVE-2024-56437MEDIUMVulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability maEPSS 0.2%CVE-2026-7993MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had EPSS 0.2%CVE-2026-7947MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised EPSS 0.2%CVE-2026-21500MEDIUMStack Overflow in iccDEV XML Calculator Macro ExpansionEPSS 0.2%CVE-2022-20338LOWIn HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This coulEPSS 0.2%CVE-2026-21501MEDIUMStack Overflow in iccDEV Calculator ParserEPSS 0.2%CVE-2026-22204MEDIUMwpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() RecipientEPSS 0.2%CVE-2026-11149HIGHInsufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromisEPSS 0.2%CVE-2024-52579MEDIUMServer-Side Request Forgery vulnerability in various APIs in MisskeyEPSS 0.2%CVE-2025-35990HIGHImproper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User ApplicationsEPSS 0.2%CVE-2026-11151HIGHInsufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had comEPSS 0.2%CVE-2026-7996MEDIUMInsufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2026-11737MEDIUMSome NETGEAR Nighthawk devices allow administrators to tamper with the deviceEPSS 0.2%