Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-32856MEDIUMDell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attackEPSS 0.1%CVE-2026-62425MEDIUMbuffer overruns in libfsimage iso9660 handlingEPSS 0.1%CVE-2026-35347MEDIUMuutils coreutils comm Silent Data Loss or Denial of Service via Improper Input ValidationEPSS 0.1%CVE-2025-6969MEDIUMability_ability_runtime an improper input validation vulnerabilityEPSS 0.1%CVE-2026-45317MEDIUMOpen WebUI: Cross-Site Request Forgery (CSRF) via Image URL ManipulationEPSS 0.1%CVE-2026-30901HIGHZoom Rooms for Windows - Improper Input ValidationEPSS 0.1%CVE-2024-0158MEDIUMDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exEPSS 0.1%CVE-2025-52651LOWHCL MyXalytics is affected by multiple security vulnerabilities.EPSS 0.1%CVE-2026-11205MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who coEPSS 0.1%CVE-2022-20512HIGHIn navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation.EPSS 0.1%CVE-2026-4407LOWOut-of-bounds array write in Xpdf 4.06 due to missing validationEPSS 0.1%CVE-2024-42424MEDIUMDell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attackeEPSS 0.1%CVE-2024-20394MEDIUMA vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DEPSS 0.1%CVE-2025-69205MEDIUMIn µURU, a Specially Crafted Federation Name Allows Dialplan InjectionEPSS 0.1%CVE-2024-38303MEDIUMDell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged aEPSS 0.1%CVE-2025-24325CRITICALImproper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticEPSS 0.1%CVE-2022-28781HIGHImproper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. TEPSS 0.1%CVE-2024-43697LOWLiteos_a has an Improper Input Validation vulnerabilityEPSS 0.1%CVE-2026-39020MEDIUMAn issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ fileEPSS 0.1%CVE-2026-8579LOWInsufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised thEPSS 0.1%