Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2025-30509MEDIUMImproper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an EPSS 0.1%CVE-2021-25510MEDIUMAn improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.EPSS 0.1%CVE-2024-45579HIGHImproper Input Validation in Camera DriverEPSS 0.1%CVE-2021-25511MEDIUMAn improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path EPSS 0.1%CVE-2024-45444MEDIUMAccess permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confEPSS 0.1%CVE-2025-20064HIGHImproper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. SysteEPSS 0.1%CVE-2024-45577HIGHImproper Input Validation in Camera DriverEPSS 0.1%CVE-2023-20634MEDIUMIn widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege withEPSS 0.1%CVE-2022-20019MEDIUMIn libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information discloEPSS 0.1%CVE-2025-31948MEDIUMImproper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applications may allow a deEPSS 0.1%CVE-2026-21088MEDIUMImproper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write EPSS 0.1%CVE-2024-51530MEDIUMLaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.1%CVE-2023-22382HIGHImproper Input Validation in AutomotiveEPSS 0.1%CVE-2026-21086MEDIUMImproper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.EPSS 0.1%CVE-2026-101131MEDIUMdeepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decisionEPSS 0.1%CVE-2024-31310HIGHIn newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill EPSS 0.1%CVE-2026-11241HIGHInsufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment EPSS 0.1%CVE-2026-58941HIGHIn multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local esEPSS 0.1%CVE-2021-25468MEDIUMA possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to readEPSS 0.1%CVE-2022-33216MEDIUMImproper Input Validation in AutomotiveEPSS 0.1%