Fallos del tipo CWE-20

5456 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2021-25356HIGHAn improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arEPSS 0.2%CVE-2021-0185HIGHImproper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a privileged user to pEPSS 0.2%CVE-2026-11233MEDIUMInsufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the reEPSS 0.2%CVE-2022-37336HIGHImproper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege vEPSS 0.2%CVE-2022-3675LOWFedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to aEPSS 0.2%CVE-2024-32860HIGHDell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attackEPSS 0.2%CVE-2026-11220MEDIUMInsufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromisEPSS 0.2%CVE-2024-32859HIGHDell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attackEPSS 0.2%CVE-2026-11261MEDIUMInappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2026-59569HIGHAndroid ZCC VPN API method privilege escalationEPSS 0.2%CVE-2024-32858HIGHDell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attackEPSS 0.2%CVE-2026-72711MEDIUMLean 4 before 4.32.2 Kernel Accepts Opaque Declaration With an Unbound Free VariableEPSS 0.2%CVE-2026-10037HIGHSandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portalEPSS 0.2%CVE-2022-29466HIGHImproper input validation in firmware for Intel(R) SPS before version SPS_E3_04.01.04.700.0 may allow an authenticated user to potentially eEPSS 0.2%CVE-2026-9157HIGHRemote Code Execution in Gmission Web FAXEPSS 0.2%CVE-2023-21502MEDIUMImproper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege eEPSS 0.2%CVE-2026-11192MEDIUMInsufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform EPSS 0.2%CVE-2026-11223MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised EPSS 0.2%CVE-2023-31035HIGHCVEEPSS 0.2%CVE-2022-37327MEDIUMImproper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 EPSS 0.2%