Fallos del tipo CWE-20

5456 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-12034HIGHInsufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacEPSS 0.2%CVE-2023-21498MEDIUMImproper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to oEPSS 0.2%CVE-2024-33611MEDIUMImproper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow a privileged user to poEPSS 0.2%CVE-2023-25175MEDIUMImproper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information dEPSS 0.2%CVE-2023-33014HIGHImproper Input Validation in ServicesEPSS 0.2%CVE-2024-21863MEDIUMDsoftbus has an improper input validation vulnerabilityEPSS 0.2%CVE-2024-52051HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17EPSS 0.2%CVE-2021-37674MEDIUMIncomplete validation in `MaxPoolGrad` in TensorFlowEPSS 0.2%CVE-2025-27493CRITICALA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < VEPSS 0.2%CVE-2022-37010LOWIn JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missedEPSS 0.2%CVE-2026-17774HIGHInsufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged networkEPSS 0.2%CVE-2022-43449MEDIUMArbitrary file read via download_server.EPSS 0.2%CVE-2025-58146CRITICALXAPI UTF-8 string handlingEPSS 0.2%CVE-2022-31616MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a loEPSS 0.2%CVE-2025-24882MEDIUMregclient may ignore pinned manifest digestsEPSS 0.2%CVE-2026-11701MEDIUMInappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2021-0185HIGHImproper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a privileged user to pEPSS 0.2%CVE-2026-11233MEDIUMInsufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the reEPSS 0.2%CVE-2023-30559MEDIUMWireless Card Firmware Improperly SignedEPSS 0.2%CVE-2022-37336HIGHImproper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege vEPSS 0.2%