Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-38420HIGHImproper Input Validation in HypervisorEPSS 0.1%CVE-2024-33031MEDIUMImproper Input Validation in RILEPSS 0.1%CVE-2023-20976HIGHIn getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application EPSS 0.1%CVE-2026-58691HIGHIn FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of prEPSS 0.1%CVE-2024-23386MEDIUMImproper Input Validation in VideoEPSS 0.1%CVE-2022-33715MEDIUMImproper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access EPSS 0.1%CVE-2025-48525HIGHIn disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated toEPSS 0.1%CVE-2025-20027HIGHImproper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System sofEPSS 0.1%CVE-2025-26426MEDIUMIn BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" packEPSS 0.1%CVE-2022-28783MEDIUMImproper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packagEPSS 0.1%CVE-2025-20068HIGHImproper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalation of privilege. SysEPSS 0.1%CVE-2025-54614MEDIUMInput verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2023-20612MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2022-23427LOWPendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media fiEPSS 0.1%CVE-2023-20613MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2026-20905MEDIUMImproper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow aEPSS 0.1%CVE-2022-32653MEDIUMIn mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution EPSS 0.1%CVE-2025-54641MEDIUMIssue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of thisEPSS 0.1%CVE-2026-21733HIGHGPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so)EPSS 0.1%CVE-2022-32652MEDIUMIn mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution EPSS 0.1%