Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-52579MEDIUMServer-Side Request Forgery vulnerability in various APIs in MisskeyEPSS 0.2%CVE-2026-7947MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised EPSS 0.2%CVE-2026-21500MEDIUMStack Overflow in iccDEV XML Calculator Macro ExpansionEPSS 0.2%CVE-2026-75975HIGHfast-uri vulnerable to server-side request forgery via malformed IPv6 normalizationEPSS 0.2%CVE-2023-27519MEDIUMImproper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable escalationEPSS 0.2%CVE-2026-14083MEDIUMInsufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scrEPSS 0.2%CVE-2024-23678HIGHDeserialization of Untrusted Data on Splunk Enterprise for Windows through Path Traversal from Separate Disk PartitionEPSS 0.2%CVE-2023-20960HIGHIn launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper inpuEPSS 0.2%CVE-2023-6381LOWImproper input validation in Newsletter Software SuperMailerEPSS 0.2%CVE-2023-49615HIGHImproper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potenEPSS 0.2%CVE-2021-26325—Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.EPSS 0.2%CVE-2025-41378MEDIUMInjection vulnerability in Iridium Certus 700EPSS 0.2%CVE-2021-3038MEDIUMGlobalProtect App: Windows VPN kernel driver denial of service (DoS)EPSS 0.2%CVE-2026-0410LOWInsufficient input validation in certain NETGEAR routersEPSS 0.2%CVE-2022-28791MEDIUMImproper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored EPSS 0.2%CVE-2025-53502MEDIUMHTML injection in FeaturedFeedsEPSS 0.2%CVE-2026-8010MEDIUMInsufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had comproEPSS 0.2%CVE-2026-11689HIGHInsufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2024-21949MEDIUMImproper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading toEPSS 0.2%CVE-2026-79025MEDIUMImproper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer procEPSS 0.2%