Fallos del tipo CWE-20

5419 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2020-7818HIGHDaviewIndy Heap Overflow VulnerabilityEPSS 1.2%CVE-2021-29468HIGHArbitrary code execution when checking out an attacker-controlled Git branchEPSS 1.2%CVE-2024-21448MEDIUMMicrosoft Teams for Android Information Disclosure VulnerabilityEPSS 1.2%CVE-2026-81995CRITICALAdobe Experience Manager Forms JEE | Improper Input Validation (CWE-20)EPSS 1.2%CVE-2024-24683MEDIUMApache Hop Engine: ID isn't escaped when generating HTMLEPSS 1.2%CVE-2018-0135—A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an EPSS 1.2%CVE-2024-12912HIGHAn improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2EPSS 1.2%CVE-2022-44617HIGHA flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly EPSS 1.2%CVE-2016-10543—call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate EPSS 1.2%CVE-2022-22727—A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact EPSS 1.2%CVE-2020-3238HIGHCisco IOx Application Framework Arbitrary File Creation VulnerabilityEPSS 1.2%CVE-2016-7073MEDIUMAn issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-EPSS 1.2%CVE-2026-50328HIGHWindows Server Update Service (WSUS) Tampering VulnerabilityEPSS 1.2%CVE-2026-26154HIGHWindows Server Update Service (WSUS) Tampering VulnerabilityEPSS 1.2%CVE-2022-22241HIGHJunos OS: Vulnerability in J-Web may allow deserialization without authenticationEPSS 1.2%CVE-2025-31233MEDIUMThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5EPSS 1.2%CVE-2021-31372HIGHJunos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.EPSS 1.2%CVE-2026-33250HIGHCrash when receiving specially-crafted packetsEPSS 1.2%CVE-2016-7074MEDIUMAn issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-EPSS 1.2%CVE-2022-4904HIGHA flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possiEPSS 1.2%