Fallos del tipo CWE-20

5462 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-21733HIGHGPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so)EPSS 0.1%CVE-2022-32653MEDIUMIn mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution EPSS 0.1%CVE-2025-54641MEDIUMIssue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of thisEPSS 0.1%CVE-2021-25457MEDIUMAn improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memoEPSS 0.1%CVE-2026-58718MEDIUMIn smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead toEPSS 0.1%CVE-2026-55332MEDIUMIn multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privEPSS 0.1%CVE-2026-55317MEDIUMIn printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privEPSS 0.1%CVE-2025-48585MEDIUMIn multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This coulEPSS 0.1%CVE-2026-0238LOWBroker VM: Improper Input Validation in Broker VM Certificate and Key FieldsEPSS 0.1%CVE-2026-56907MEDIUMIn VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with EPSS 0.1%CVE-2025-51619MEDIUMA vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-serviceEPSS 0.1%CVE-2026-0015MEDIUMIn multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lEPSS 0.1%CVE-2025-48587MEDIUMIn multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This coulEPSS 0.1%CVE-2026-56932MEDIUMIn Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could lead to local escalatioEPSS 0.1%CVE-2026-0034HIGHIn setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. ThEPSS 0.1%CVE-2026-20901MEDIUMImproper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adEPSS 0.1%CVE-2023-32811MEDIUMIn connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalationEPSS 0.1%CVE-2025-48647HIGHIn cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. EPSS 0.1%CVE-2025-48624HIGHIn multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local eEPSS 0.1%CVE-2026-55273HIGHIn AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to EPSS 0.1%