Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-13808MEDIUMInsufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentiallyEPSS 0.1%CVE-2025-7378MEDIUMAn improper input validation vulnerability was found on manipulating configuration of ADMEPSS 0.1%CVE-2025-24486HIGHImproper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticEPSS 0.1%CVE-2025-24484HIGHImproper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticEPSS 0.1%CVE-2026-81686MEDIUMopenssl_encrypt before 1.4.9 D-Bus Properties Authorization BypassEPSS 0.1%CVE-2022-27829HIGHImproper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2022-27830HIGHImproper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2025-26474LOWcommunication_ipc an improper input validation vulnerabilityEPSS 0.1%CVE-2025-32004LOWImproper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalatiEPSS 0.1%CVE-2025-20096MEDIUMImproper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adveEPSS 0.1%CVE-2026-12456MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2022-39880HIGHImproper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary EPSS 0.1%CVE-2026-84666MEDIUMJenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration thEPSS 0.1%CVE-2026-12191HIGHComma AI Openpilot Pickle modeld.py pickle.loads deserializationEPSS 0.1%CVE-2022-20457MEDIUMIn getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validatiEPSS 0.1%CVE-2025-24005HIGHLocal Privilege Escalation via Vulnerable SSH ScriptEPSS 0.1%CVE-2025-21086MEDIUMImproper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticEPSS 0.1%CVE-2022-20542HIGHIn parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation EPSS 0.1%CVE-2023-28574CRITICALImproper Input Validation in CoreEPSS 0.1%CVE-2022-30754HIGHImplicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities witEPSS 0.1%