Fallos del tipo CWE-20

5456 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2021-26404MEDIUMImproper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. EPSS 0.2%CVE-2023-21439HIGHImproper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activitieEPSS 0.2%CVE-2026-16422HIGHInsufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileEPSS 0.2%CVE-2022-38787MEDIUMImproper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentiEPSS 0.2%CVE-2024-31158HIGHImproper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable esEPSS 0.2%CVE-2022-34147HIGHImproper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, Intel(R) NUC PerformaEPSS 0.2%CVE-2022-36339HIGHImproper input validation in firmware for Intel(R) NUC 8 Compute Element, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element mEPSS 0.2%CVE-2022-25976MEDIUMImproper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable deniEPSS 0.2%CVE-2024-31959HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native hanEPSS 0.2%CVE-2022-23817HIGHInsufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application toEPSS 0.2%CVE-2023-30440MEDIUMIBM PowerVM Hypervisor denial of serviceEPSS 0.2%CVE-2021-25485HIGHPath traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT EPSS 0.2%CVE-2025-2223HIGHCWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineeringEPSS 0.2%CVE-2026-60648HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2021-25414—Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbEPSS 0.2%CVE-2026-11280MEDIUMInappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via aEPSS 0.2%CVE-2024-31154HIGHImproper input validation in UEFI firmware for some Intel(R) Server S2600BPBR may allow a privileged user to potentially enable escalation oEPSS 0.2%CVE-2025-53471MEDIUMEmerson ValveLink Products Improper Input ValidationEPSS 0.2%CVE-2026-11259MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin pEPSS 0.2%CVE-2025-33043MEDIUMSMM buffer IntegrityEPSS 0.2%