Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-11273MEDIUMInsufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a userEPSS 0.2%CVE-2024-37027MEDIUMImproper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentiallEPSS 0.2%CVE-2026-32603HIGHSandboxie kernel driver denial of service via malformed IOCTL from sandboxed processEPSS 0.2%CVE-2026-17870MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment EPSS 0.2%CVE-2026-17844MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment EPSS 0.2%CVE-2026-7961MEDIUMInsufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network sEPSS 0.2%CVE-2023-4753LOWOpenHarmony v3.2.1 and prior version has a system call function usage errorEPSS 0.2%CVE-2026-21768MEDIUMHCL Verse for Android is susceptible to an injection vulnerabilityEPSS 0.2%CVE-2023-24465MEDIUMCommunication Wi-Fi  subsystem has a null pointer reference vulnerability when receving external data.EPSS 0.2%CVE-2026-21071MEDIUMImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memorEPSS 0.2%CVE-2026-1858MEDIUMwget2 Improper Certificate ValidationEPSS 0.2%CVE-2026-21072MEDIUMImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2026-21066MEDIUMImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2025-11934LOWImproper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerifyEPSS 0.2%CVE-2021-37673MEDIUM`CHECK`-fail in `MapStage` in TensorFlowEPSS 0.2%CVE-2024-55567HIGHImproper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62EPSS 0.2%CVE-2026-11126MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicEPSS 0.2%CVE-2026-11286MEDIUMInsufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2024-10083MEDIUMCWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver inEPSS 0.2%CVE-2026-21065MEDIUMOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%