Fallos del tipo CWE-20

5459 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-53409HIGHImproper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of priEPSS 0.2%CVE-2026-22568MEDIUMUnauthorized information retrieval in ZIA Admin UIEPSS 0.2%CVE-2023-21451MEDIUMA Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.EPSS 0.2%CVE-2023-39251MEDIUM Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vEPSS 0.2%CVE-2026-45329HIGHESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service WrappersEPSS 0.2%CVE-2026-55371MEDIUMOpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_lengthEPSS 0.2%CVE-2024-34163HIGHImproper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via locEPSS 0.2%CVE-2023-31028LOW NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a EPSS 0.2%CVE-2021-22280HIGHDLL Hijacking Vulnerability in Automation StudioEPSS 0.2%CVE-2025-4424MEDIUMSetupAutomationSmm : Arbitrary calls to SmmSetVariable with unsanitised arguments in SMI handlerEPSS 0.2%CVE-2026-45676MEDIUMOpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agentEPSS 0.2%CVE-2024-21781HIGHImproper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or deniEPSS 0.2%CVE-2026-1225LOWMalicious logback.xml configuration file allows instantiation of arbitrary classesEPSS 0.2%CVE-2026-11686LOWInsufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had comprEPSS 0.2%CVE-2026-24348HIGHMultiple cross-site scripting vulnerabilities in EZCast Pro II DongleEPSS 0.2%CVE-2026-43724HIGHThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.EPSS 0.2%CVE-2025-71011MEDIUMAn input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allowsEPSS 0.2%CVE-2025-71009MEDIUMAn input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of SerEPSS 0.2%CVE-2021-25450MEDIUMPath traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remEPSS 0.2%CVE-2025-31980MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%