Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-33216MEDIUMImproper Input Validation in AutomotiveEPSS 0.1%CVE-2024-51519MEDIUMVulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.1%CVE-2026-20767HIGHImproper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow EPSS 0.1%CVE-2025-62816MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP iEPSS 0.1%CVE-2024-45446MEDIUMAccess permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect aEPSS 0.1%CVE-2025-52347HIGHAn issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 BuEPSS 0.1%CVE-2026-61079MEDIUMVulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 2EPSS 0.1%CVE-2025-48612HIGHIn setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment settiEPSS 0.1%CVE-2022-27833MEDIUMImproper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.EPSS 0.1%CVE-2022-20392HIGHIn declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent dEPSS 0.1%CVE-2026-101079LOWagentverus agentverus-scanner context.js isSecurityDefenseSkill reliance on untrusted inputs in a security decisionEPSS 0.1%CVE-2022-36850MEDIUMPath traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.EPSS 0.1%CVE-2024-51529MEDIUMData verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.EPSS 0.1%CVE-2025-21460HIGHImproper Input Validation in Automotive Software platform based on QNXEPSS 0.1%CVE-2021-25512MEDIUMAn improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2024-49845HIGHImproper Input Validation in HLOSEPSS 0.1%CVE-2023-20932LOWIn onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input valEPSS 0.1%CVE-2024-49844HIGHImproper Input Validation in AutomotiveEPSS 0.1%CVE-2025-48638HIGHIn __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalaEPSS 0.1%CVE-2025-48623HIGHIn init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalatiEPSS 0.1%