Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-17736MEDIUMInsufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had cEPSS 0.2%CVE-2026-17908MEDIUMInsufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had EPSS 0.2%CVE-2025-43195MEDIUMAn issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS SEPSS 0.2%CVE-2026-7953MEDIUMInsufficient validation of untrusted input in Omnibox in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary EPSS 0.2%CVE-2025-46266MEDIUMUnauthenticated Transmission of Data in NomadBranch.exeEPSS 0.2%CVE-2026-11031MEDIUMInsufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform EPSS 0.2%CVE-2026-19503MEDIUMInsufficient OIDC endpoint validation could invoke unintended local protocol handlersEPSS 0.2%CVE-2025-12278MEDIUMLogout Functionality not WorkingEPSS 0.2%CVE-2026-11697CRITICALInsufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform aEPSS 0.2%CVE-2026-22748MEDIUMPotential Security Misconfiguration when Using withIssuerLocationEPSS 0.2%CVE-2026-7934MEDIUMInsufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had comproEPSS 0.2%CVE-2023-25776MEDIUMImproper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information dEPSS 0.2%CVE-2026-11246MEDIUMInsufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromiseEPSS 0.2%CVE-2025-59596MEDIUMCVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14EPSS 0.2%CVE-2024-39827MEDIUMZoom Workplace Desktop App for Windows - Improper Input ValidationEPSS 0.2%CVE-2024-21925HIGHImproper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code exEPSS 0.2%CVE-2024-42410MEDIUMImproper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via locaEPSS 0.2%CVE-2024-0179HIGHSMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentiaEPSS 0.2%CVE-2026-46243HIGHsmb: client: reject userspace cifs.spnego descriptionsEPSS 0.2%CVE-2023-40394LOWThe issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be abEPSS 0.2%