Fallos del tipo CWE-20

5456 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-32490HIGH Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabilEPSS 0.2%CVE-2025-44779MEDIUMAn issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.EPSS 0.2%CVE-2022-42534HIGHIn trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible privilege escalation due to improper input validation. This could leadEPSS 0.2%CVE-2026-13006HIGHIncomplete protection against CVE-2025-11226EPSS 0.2%CVE-2025-66225HIGHOrangeHRM is Vulnerable to Account Takeover Through Unvalidated Username in Password Reset WorkflowEPSS 0.2%CVE-2025-33221MEDIUMNVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission EPSS 0.2%CVE-2022-37327MEDIUMImproper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 EPSS 0.2%CVE-2024-3173HIGHInsufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escaEPSS 0.2%CVE-2024-36482HIGHImproper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2022-32144HIGHThere is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to serviEPSS 0.2%CVE-2023-32633MEDIUMImproper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially eEPSS 0.2%CVE-2026-60640HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2023-25772MEDIUMImproper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may allow an authenticateEPSS 0.2%CVE-2024-27240HIGHZoom Apps for Windows - Improper Input ValidationEPSS 0.2%CVE-2023-25522HIGH NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by providing configuratiEPSS 0.2%CVE-2026-10942HIGHInappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform privilege escalatiEPSS 0.2%CVE-2022-20592MEDIUMIn ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local iEPSS 0.2%CVE-2026-76816LOWNetty: MQTT Topic Name and Client ID Validation BypassEPSS 0.2%CVE-2022-20590MEDIUMIn valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lEPSS 0.2%CVE-2025-68134HIGHEVerest's use of assert functions can potentially lead to denial of serviceEPSS 0.2%