Fallos del tipo CWE-20

5421 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-30232HIGHA CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercEPSS 1.2%CVE-2021-29431HIGHSSRF in Sydent due to missing validation of hostnamesEPSS 1.2%CVE-2024-22065MEDIUMZTE MF258 Pro product has a OS Command injection vulnerabilityEPSS 1.2%CVE-2023-2454HIGHschema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attackeEPSS 1.2%CVE-2021-20222—A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highesEPSS 1.2%CVE-2025-64986HIGHCommand Injection in 1E-Explorer-TachyonCore-DevicesListeningOnAPort InstructionEPSS 1.2%CVE-2021-39193MEDIUMTransaction validity oversight in pallet-ethereumEPSS 1.2%CVE-2023-35619MEDIUMMicrosoft Outlook for Mac Spoofing VulnerabilityEPSS 1.2%CVE-2018-10908MEDIUMIt was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafEPSS 1.2%CVE-2018-15632HIGHImproper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote EPSS 1.2%CVE-2021-25745HIGHIngress-nginx path can be pointed to service account token fileEPSS 1.2%CVE-2023-28330MEDIUMMoodle: authenticated arbitrary file read through malformed backup fileEPSS 1.2%CVE-2026-0404MEDIUMInsufficient input validation in NETGEAR Orbi routersEPSS 1.2%CVE-2020-7823HIGHDaviewIndy Multiple VulnerabilitiesEPSS 1.2%CVE-2024-31867MEDIUMApache Zeppelin: LDAP search filter query Injection VulnerabilityEPSS 1.2%CVE-2023-6879CRITICALheap buffer overflow in libaomEPSS 1.2%CVE-2024-29831HIGHApache DolphinScheduler: RCE by arbitrary js executionEPSS 1.2%CVE-2023-29335HIGHMicrosoft Word Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2022-24711CRITICALRemote CLI Command Execution Vulnerability in CodeIgniter4EPSS 1.2%CVE-2024-8755HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 1.2%