Fallos del tipo CWE-20

5456 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-28126MEDIUMImproper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to poEPSS 0.2%CVE-2024-22382HIGHImproper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged usEPSS 0.2%CVE-2025-12908MEDIUMInsufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perfEPSS 0.2%CVE-2024-29074MEDIUMTelephony has an improper input validation vulnerabilityEPSS 0.2%CVE-2026-11034MEDIUMInsufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker toEPSS 0.2%CVE-2024-28947HIGHImproper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow aEPSS 0.2%CVE-2022-20507HIGHIn onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds cEPSS 0.2%CVE-2024-13943HIGHTesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape VulnerabilityEPSS 0.2%CVE-2025-31488MEDIUMPlain Craft Launcher's custom homepage can use Internet Explorer to load web pages with the help of controls such as WebBrowserEPSS 0.2%CVE-2026-45328CRITICALESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service WrappersEPSS 0.2%CVE-2025-58114MEDIUMPotential XSS in Extension:CognitiveProcessDesignerEPSS 0.2%CVE-2026-12453MEDIUMInsufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2026-82738MEDIUMAsh.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of serviceEPSS 0.2%CVE-2026-12034HIGHInsufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacEPSS 0.2%CVE-2024-52880HIGHAn issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before versioEPSS 0.2%CVE-2026-82740LOWAsh.Type ignores outer array constraints on nested {:array, {:array, type}} inputsEPSS 0.2%CVE-2026-65979MEDIUMOpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN)EPSS 0.2%CVE-2026-0416MEDIUMImproper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionalityEPSS 0.2%CVE-2022-42269HIGHNVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged lEPSS 0.2%CVE-2022-34443HIGH Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attaEPSS 0.2%