Fallos del tipo CWE-20

5421 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-22525HIGHCommand injection in restore function of Carlo Gavazzi UWP3.0 allows for command injectionEPSS 1.2%CVE-2017-12297—A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka EPSS 1.2%CVE-2025-31281CRITICALAn input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, EPSS 1.2%CVE-2020-7803HIGHZoneplayer ActiveX File Download VulnerabilityEPSS 1.2%CVE-2020-7822HIGHDaviewIndy Multiple VulnerabilitiesEPSS 1.2%CVE-2024-40518HIGHSeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the useEPSS 1.2%CVE-2020-25151—The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack on the NIO 50 (all EPSS 1.2%CVE-2017-12299—A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall ServEPSS 1.2%CVE-2021-1465MEDIUMA vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to condEPSS 1.2%CVE-2024-34365CRITICALApache Karaf Cave: Cave SSRF and arbitrary file accessEPSS 1.2%CVE-2022-44644MEDIUMApache Linkis (incubating): The DatasourceManager module has a Local File Read VulnerabilityEPSS 1.2%CVE-2025-64988HIGHCommand Injection in 1E-Nomad-GetCmContentLocations InstructionEPSS 1.2%CVE-2025-64987HIGHCommand Injection in 1E-Explorer-TachyonCore-CheckSimpleIoC InstructionEPSS 1.2%CVE-2026-4987HIGHSureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'EPSS 1.2%CVE-2021-36335MEDIUMDell EMC CloudLink 7.1 and all prior versions contain an Improper Input Validation Vulnerability. A remote low privileged attacker, may poteEPSS 1.2%CVE-2021-3567—A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applicationsEPSS 1.2%CVE-2022-25940HIGHDenial of Service (DoS)EPSS 1.2%CVE-2020-3567MEDIUMCisco Industrial Network Director Denial of Service VulnerabilityEPSS 1.2%CVE-2020-8475MEDIUMABB Central Licensing System - Denial of Service VulnerabilityEPSS 1.2%CVE-2023-26364MEDIUMDenial of Service of regular expression in package @adobe/css-toolsEPSS 1.2%