Fallos del tipo CWE-20

5456 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-11213CRITICALInsufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromEPSS 0.2%CVE-2025-12284MEDIUMLack of Input ValidationEPSS 0.2%CVE-2026-13812MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who coEPSS 0.2%CVE-2022-23403MEDIUMImproper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2025-46836MEDIUMnet-tools Stack-based Buffer Overflow vulnerabilityEPSS 0.2%CVE-2022-48189MEDIUMAn SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privEPSS 0.2%CVE-2026-7989MEDIUMInsufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendeEPSS 0.2%CVE-2025-11226HIGHConditional processing of logback.xml configuration file, in conjuction with Spring Framework and JaninoEPSS 0.2%CVE-2025-12001CRITICALIncorrect Content-Type HeaderEPSS 0.2%CVE-2025-31966LOWBoolean-Based SQL Injection in Multiple Unica ComponentsEPSS 0.2%CVE-2022-30542HIGHImproper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System EPSS 0.2%CVE-2026-11237HIGHInsufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2026-19655HIGHOn affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthentEPSS 0.2%CVE-2026-28421MEDIUMVim has a heap-buffer-overflow and a segmentation faultEPSS 0.2%CVE-2025-11676HIGHUPnP DOS in TL-WR940N V6EPSS 0.2%CVE-2023-38719MEDIUMIBM Db2 denial of serviceEPSS 0.2%CVE-2026-100699MEDIUMNodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 CommentEPSS 0.2%CVE-2026-60650HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2023-22342HIGHImproper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to poteEPSS 0.2%CVE-2024-33657HIGHSmm Callout in SmmComputrace ModuleEPSS 0.2%