Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-21065MEDIUMOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2026-43722MEDIUMThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.EPSS 0.2%CVE-2024-22338MEDIUMIBM Security Verify Access OIDC Provider information disclosureEPSS 0.2%CVE-2024-39811MEDIUMImproper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalatiEPSS 0.2%CVE-2024-41167HIGHImproper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to potentially enable EPSS 0.2%CVE-2026-34383MEDIUMAdmidio: CSRF and Form Validation Bypass in Inventory Item Save via `imported` ParameterEPSS 0.2%CVE-2024-38483MEDIUMDell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local acEPSS 0.2%CVE-2026-35369MEDIUMuutils coreutils kill System-wide Process Termination and Denial of Service via Argument MisinterpretationEPSS 0.2%CVE-2026-20627MEDIUMAn issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.EPSS 0.2%CVE-2026-78237HIGHInsufficient input validation in Admin By Request (ABR)EPSS 0.2%CVE-2026-43895MEDIUMjq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifactsEPSS 0.2%CVE-2025-24296MEDIUMImproper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial ofEPSS 0.1%CVE-2026-60526MEDIUMVulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. EPSS 0.1%CVE-2023-31366LOWImproper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of EPSS 0.1%CVE-2026-56975MEDIUMIn Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denEPSS 0.1%CVE-2017-3772MEDIUMA vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.EPSS 0.1%CVE-2026-30769HIGHAn issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sEPSS 0.1%CVE-2026-11221MEDIUMInsufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromiEPSS 0.1%CVE-2025-6969MEDIUMability_ability_runtime an improper input validation vulnerabilityEPSS 0.1%CVE-2026-62425MEDIUMbuffer overruns in libfsimage iso9660 handlingEPSS 0.1%