Fallos del tipo CWE-20

5416 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-2727MEDIUMBypassing policies imposed by the ImagePolicyWebhook admission pluginEPSS 1.1%CVE-2026-20856HIGHWindows Server Update Service (WSUS) Remote Code Execution VulnerabilityEPSS 1.1%CVE-2019-15613—A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.EPSS 1.1%CVE-2025-34129HIGHLILIN DVR RCE via Malicious FTP/NTP ConfigurationEPSS 1.1%CVE-2022-46836CRITICALPHP code injection in watolibEPSS 1.1%CVE-2026-48316CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 1.1%CVE-2018-19945—Improper Limitation of a Pathname to a Restricted Directory in QTSEPSS 1.1%CVE-2021-32697MEDIUMForm validation can be skippedEPSS 1.1%CVE-2022-27655—When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version EPSS 1.1%CVE-2022-27654—When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versiEPSS 1.1%CVE-2023-22934HIGHSPL Command Safeguards Bypass via the ‘pivot’ SPL Command in Splunk EnterpriseEPSS 1.1%CVE-2023-3705HIGHInformation Disclosure Vulnerability in CP-Plus Network Video RecorderEPSS 1.1%CVE-2020-7518—A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modEPSS 1.1%CVE-2018-15429—Cisco HyperFlex HX Data Platform Software Unauthorized Directory Access VulnerabilityEPSS 1.1%CVE-2026-50632HIGHApache CXF: JNDI Injection Vulnerability in JMSConfigFactoryEPSS 1.1%CVE-2023-26281MEDIUMIBM HTTP Server denial of serviceEPSS 1.1%CVE-2022-21796CRITICALA memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A speciaEPSS 1.1%CVE-2023-48631MEDIUMDenial of Service of regular expression in package @adobe/css-toolsEPSS 1.1%CVE-2018-1110—A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.EPSS 1.1%CVE-2024-1481MEDIUMFreeipa: specially crafted http requests potentially lead to denial of serviceEPSS 1.1%