Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2020-3164MEDIUMCisco ESA, Cisco WSA, and Cisco SMA GUI Denial of Service VulnerabilityEPSS 1.3%CVE-2021-40127MEDIUMCisco Small Business 200, 300, and 500 Series Switches Web-Based Management Interface Denial of Service VulnerabilityEPSS 1.3%CVE-2024-32007HIGHApache CXF Denial of Service vulnerability in JOSEEPSS 1.3%CVE-2024-38194HIGHAzure Web Apps Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2019-10937—A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to the device could causeEPSS 1.3%CVE-2022-21646HIGHLookup operations do not take into account wildcards in SpiceDBEPSS 1.3%CVE-2017-12701—BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authentEPSS 1.3%CVE-2022-25271—Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validationEPSS 1.3%CVE-2022-39266CRITICALisolated-vm has vulnerable CachedDataOptions in APIEPSS 1.3%CVE-2021-34736MEDIUMCisco Integrated Management Controller GUI Denial of Service VulnerabilityEPSS 1.3%CVE-2023-20009MEDIUMA vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) coEPSS 1.3%CVE-2022-39353CRITICALxmldom allows multiple root nodes in a DOMEPSS 1.3%CVE-2026-50633HIGHApache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImplEPSS 1.3%CVE-2021-26617HIGHGabia Firstmall remote code execution vulnerabilityEPSS 1.3%CVE-2026-75638MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 1.3%CVE-2018-19952—If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP SystEPSS 1.3%CVE-2024-5171CRITICALheap buffer overflow in libaomEPSS 1.3%CVE-2023-35798—Airflow Apache ODBC and MSSQL Providers Arbitrary File Read VulnerabilityEPSS 1.3%CVE-2018-3776—Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit loEPSS 1.3%CVE-2023-46116CRITICALRemote Code Execution via insufficiently sanitized call to shell.openExternalEPSS 1.3%