Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-33704HIGHImproper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activitiEPSS 0.1%CVE-2025-48638HIGHIn __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalaEPSS 0.1%CVE-2024-23706HIGHIn multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local eEPSS 0.1%CVE-2026-27765MEDIUMImproper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User ApplicationEPSS 0.1%CVE-2024-0022MEDIUMIn multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another usEPSS 0.1%CVE-2026-77797LOWVelociraptor Prefetch parser out of boundsEPSS 0.1%CVE-2026-21089MEDIUMImproper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-ofEPSS 0.1%CVE-2026-17503MEDIUMThis Power System update is being released to addressEPSS 0.1%CVE-2025-29936HIGHImproper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentiEPSS 0.1%CVE-2026-7997HIGHInsufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local attacker to perform OS-EPSS 0.1%CVE-2026-7990HIGHInsufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to performEPSS 0.1%CVE-2026-13849HIGHInsufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to poteEPSS 0.1%CVE-2026-20913MEDIUMImproper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escEPSS 0.1%CVE-2024-58044HIGHPermission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect avaEPSS 0.1%CVE-2025-68964MEDIUMData verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-14963MEDIUMA vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevatedEPSS 0.1%CVE-2024-38420HIGHImproper Input Validation in HypervisorEPSS 0.1%CVE-2024-43052HIGHImproper Input Validation in Video Analytics and ProcessingEPSS 0.1%CVE-2021-25500HIGHA missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.EPSS 0.1%CVE-2024-38413MEDIUMImproper Input Validation in Computer VisionEPSS 0.1%