Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-43545CRITICALA vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER MEPSS 1.5%CVE-2023-50262MEDIUMDompdf possible DoS caused by infinite recursion when parsing SVG imagesEPSS 1.5%CVE-2022-24093CRITICALAdobe Commerce post-auth improper input validation leads to remote code executionEPSS 1.5%CVE-2019-1951MEDIUMCisco SD-WAN Solution Packet Filtering Bypass VulnerabilityEPSS 1.5%CVE-2023-35303HIGHUSB Audio Class System Driver Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-24774HIGHImproper Input Validation leading to Path Traversal in CycloneDX BOM Repository ServerEPSS 1.5%CVE-2022-1053—Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and tEPSS 1.5%CVE-2023-49291CRITICALImproper Sanitization of Branch Name Leads to Arbitrary Code InjectionEPSS 1.4%CVE-2025-30471HIGHA validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, maEPSS 1.4%CVE-2026-77547CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 1.4%CVE-2026-47367CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID EnterpEPSS 1.4%CVE-2026-77548CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi ProtEPSS 1.4%CVE-2026-77543CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 1.4%CVE-2026-77546CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 1.4%CVE-2026-47370CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 1.4%CVE-2026-77533CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi ProtEPSS 1.4%CVE-2025-34105CRITICALDiskBoss Enterprise Stack-Based Buffer Overflow RCEEPSS 1.4%CVE-2026-33000CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS EPSS 1.4%CVE-2022-24280MEDIUMApache Pulsar Proxy target broker address isn't validatedEPSS 1.4%CVE-2021-1263HIGHCisco SD-WAN Command Injection VulnerabilitiesEPSS 1.4%