Fallos del tipo CWE-20

5456 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-32617HIGHImproper input validation in some Intel(R) NUC Rugged Kit, Intel(R) NUC Kit and Intel(R) Compute Element BIOS firmware may allow a privilegeEPSS 0.2%CVE-2024-36282HIGHImproper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged EPSS 0.2%CVE-2026-16643MEDIUMLunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086EPSS 0.2%CVE-2026-15088MEDIUMDevelopment Environment - Critical - Unsupported - SA-CONTRIB-2026-089EPSS 0.2%CVE-2026-18261MEDIUMPowerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092EPSS 0.2%CVE-2022-42477MEDIUMAn improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may EPSS 0.2%CVE-2026-17970MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network EPSS 0.2%CVE-2026-13999MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user toEPSS 0.2%CVE-2026-43989HIGHJunoClaw: upload_wasm accepted arbitrary filesystem paths without validationEPSS 0.2%CVE-2026-73768HIGHLocal Privilege Escalation in AOS-CX Command Line InterfaceEPSS 0.2%CVE-2024-21871HIGHImproper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privEPSS 0.2%CVE-2026-11240LOWInsufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2024-0127HIGHNVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of thEPSS 0.2%CVE-2026-87071MEDIUMForminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted PostsEPSS 0.2%CVE-2026-11251LOWInsufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2021-26404MEDIUMImproper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. EPSS 0.2%CVE-2022-38787MEDIUMImproper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentiEPSS 0.2%CVE-2022-28699HIGHImproper input validation for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via EPSS 0.2%CVE-2023-21439HIGHImproper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activitieEPSS 0.2%CVE-2026-16422HIGHInsufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileEPSS 0.2%