Fallos del tipo CWE-20

5465 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-11297HIGHInsufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to bypEPSS 0.1%CVE-2024-20056MEDIUMIn preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilegeEPSS 0.1%CVE-2023-21092HIGHIn retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of SyEPSS 0.1%CVE-2025-48559MEDIUMIn multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could EPSS 0.1%CVE-2025-48644MEDIUMIn multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial ofEPSS 0.1%CVE-2025-11195LOWRapid7 AppSpider Project Name Validation BypassEPSS 0.1%CVE-2026-102677HIGHElectron: Sandboxed preload code cache can be poisoned by a compromised rendererEPSS 0.1%CVE-2025-48556HIGHIn multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. ThEPSS 0.1%CVE-2025-48541HIGHIn onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. EPSS 0.1%CVE-2025-22424HIGHIn multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escaEPSS 0.1%CVE-2025-54636MEDIUMIssue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of thEPSS 0.1%CVE-2025-47314HIGHImproper Input Validation in Automotive Software platform based on QNXEPSS 0.1%CVE-2026-28578MEDIUMIn multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. ThisEPSS 0.1%CVE-2025-36920HIGHIn hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead tEPSS 0.1%CVE-2024-32903HIGHIn prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead EPSS 0.1%CVE-2025-27040MEDIUMImproper Input Validation in TZ FirmwareEPSS 0.1%CVE-2025-48538MEDIUMIn setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to impropeEPSS 0.1%CVE-2025-48643HIGHIn multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of priviEPSS 0.1%CVE-2026-11158HIGHInsufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentialEPSS 0.1%CVE-2025-32322HIGHIn onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screeEPSS 0.1%