Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2020-3527HIGHCisco Catalyst 9200 Series Switches Jumbo Frame Denial of Service VulnerabilityEPSS 1.4%CVE-2019-15289HIGHCisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service VulnerabilitiesEPSS 1.4%CVE-2019-15261HIGHCisco Aironet Access Points Point-to-Point Tunneling Protocol Denial of Service VulnerabilityEPSS 1.4%CVE-2022-1727HIGHImproper Input Validation in jgraph/drawioEPSS 1.4%CVE-2024-9042MEDIUMThis CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listeEPSS 1.4%CVE-2023-30449HIGHIBM Db2 denial of serviceEPSS 1.4%CVE-2018-16561HIGHA vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication EPSS 1.4%CVE-2023-30445HIGHIBM Db2 denial of serviceEPSS 1.4%CVE-2024-45058HIGHPrivilege escalation in i-EducarEPSS 1.4%CVE-2024-31862MEDIUMApache Zeppelin: Denial of service with invalid notebook nameEPSS 1.4%CVE-2024-7014HIGHImproper multimedia file attachment validation in Telegram for Android appEPSS 1.4%CVE-2018-12474MEDIUMCrafted service parameters allows to induce unexpected behaviour in obs-service-tar_scmEPSS 1.4%CVE-2018-10843HIGHsource-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to EPSS 1.4%CVE-2024-26189HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 1.4%CVE-2019-1905MEDIUMCisco Email Security Appliance GZIP Content Filter Bypass VulnerabilityEPSS 1.4%CVE-2020-7849HIGHUPRISM CURIX arbitrary code execution vulnerabilityEPSS 1.4%CVE-2024-3884HIGHUndertow: outofmemory when parsing form data encoding with application/x-www-form-urlencodedEPSS 1.4%CVE-2019-1678MEDIUMCisco Meeting Server Denial of Service VulnerabilityEPSS 1.4%CVE-2023-30448MEDIUMIBM Db2 denial of serviceEPSS 1.4%CVE-2025-12543CRITICALUndertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrfEPSS 1.4%