Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-0567—A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bEPSS 1.0%CVE-2022-22539—When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versionEPSS 1.0%CVE-2021-30501—An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of servEPSS 1.0%CVE-2018-10921MEDIUMCertain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially lead to corruption of EPSS 1.0%CVE-2021-26631HIGHMangboard parameter modulation vulnerabilityEPSS 1.0%CVE-2026-45495HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-75634MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 1.0%CVE-2026-76194MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 1.0%CVE-2021-20330MEDIUMSpecific replication command with malformed oplog entries can crash secondariesEPSS 1.0%CVE-2021-22787HIGHA CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a speciallyEPSS 1.0%CVE-2023-5188HIGHWAGO Improper Input Validation in IEC61850 Server / TelecontrolEPSS 1.0%CVE-2026-20224HIGHCisco Catalyst SD-WAN Manager XML External Entity Injection VulnerabilityEPSS 1.0%CVE-2024-26181MEDIUMWindows Kernel Denial of Service VulnerabilityEPSS 1.0%CVE-2013-4144—There is an object injection vulnerability in swfupload plugin for wordpress.EPSS 1.0%CVE-2021-42121MEDIUMDenial of Service via Invalid Date Format in TopEaseEPSS 1.0%CVE-2021-1221MEDIUMCisco Webex Meetings and Cisco Webex Meetings Server Software Hyperlink Injection VulnerabilityEPSS 1.0%CVE-2024-20684MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 1.0%CVE-2021-22678—Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory EPSS 1.0%CVE-2024-0710MEDIUMGP Unique ID <= 1.5.5 - Unauthenticated Form Submission Unique ID ModificationEPSS 1.0%CVE-2020-2504MEDIUMAbsolute path traversal vulnerability in QESEPSS 1.0%