Fallos del tipo CWE-20

5455 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-0179HIGHSMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentiaEPSS 0.2%CVE-2025-8075MEDIUMImproper Input ValidationEPSS 0.2%CVE-2024-23487HIGHImproper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a priviEPSS 0.2%CVE-2026-11078MEDIUMInappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2023-41782LOWDLL Hijacking Vulnerability in ZTE ZXCLOUD iRAIEPSS 0.2%CVE-2026-52876HIGHStreambert: Arbitrary File Execution via VLC/mpv Launcher FallbackEPSS 0.2%CVE-2026-11283MEDIUMInsufficient validation of untrusted input in Shortcuts in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to bypass nEPSS 0.2%CVE-2022-38102HIGHImproper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may alEPSS 0.2%CVE-2026-9903MEDIUMInsufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compEPSS 0.2%CVE-2023-43799MEDIUMThe Altair Desktop Client Does Not Sanitize External URLs before passing them to the underlying systemEPSS 0.2%CVE-2022-34460HIGH Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit tEPSS 0.2%CVE-2026-87568MEDIUMImproper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-22567HIGHZIA Admin UI Input Validation BugEPSS 0.2%CVE-2026-11218MEDIUMInappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convincEPSS 0.2%CVE-2026-21505MEDIUMiccDEV has Undefined Behavior (UB) - Invalid Enum ValueEPSS 0.2%CVE-2026-21678HIGHiccDEV has heap-buffer-overflow vulnerability on IccTagXml()EPSS 0.2%CVE-2026-0903MEDIUMInappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous fEPSS 0.2%CVE-2025-54368MEDIUMuv is vulnerable to ZIP payload obfuscation through parsing differentialsEPSS 0.2%CVE-2025-5148MEDIUMFunAudioLLM InspireMusic Pickle Data model.py load_state_dict deserializationEPSS 0.2%CVE-2026-40317CRITICALNovumOS has Privilege Escalation in the Syscall InterfaceEPSS 0.2%