Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2021-23035—On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked respEPSS 0.9%CVE-2021-35533HIGHSpecially Crafted IEC 60870-5-104 Packet Vulnerability in RTU500 seriesEPSS 0.9%CVE-2021-23034—On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual seEPSS 0.9%CVE-2021-23039—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configEPSS 0.9%CVE-2024-20659HIGHWindows Hyper-V Security Feature Bypass VulnerabilityEPSS 0.9%CVE-2021-20326MEDIUMSpecially crafted query may result in a denial of service of mongodEPSS 0.9%CVE-2023-49082MEDIUMaiohttp's ClientSession is vulnerable to CRLF injection via methodEPSS 0.9%CVE-2022-28328—A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALAEPSS 0.9%CVE-2021-22277HIGHAC 800M MMS - Denial of Service vulnerability in MMS communicationEPSS 0.9%CVE-2020-10715—A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbEPSS 0.9%CVE-2025-47777CRITICAL5ire Client Vulnerable to Cross-Site Scripting (XSS) and Remote Code Execution (RCE)EPSS 0.9%CVE-2022-43723HIGHA vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software dEPSS 0.9%CVE-2021-1220MEDIUMCisco IOS XE Software Web UI Denial of Service VulnerabilitiesEPSS 0.9%CVE-2021-1356MEDIUMCisco IOS XE Software Web UI Denial of Service VulnerabilitiesEPSS 0.9%CVE-2020-15190MEDIUMSegfault in TensorflowEPSS 0.9%CVE-2022-36362HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versionsEPSS 0.9%CVE-2022-45872CRITICALiTerm2 before 3.4.18 mishandles a DECRQSS response.EPSS 0.9%CVE-2024-52831LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.9%CVE-2024-43755LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.9%CVE-2021-1286MEDIUMCisco Data Center Network Manager VulnerabilitiesEPSS 0.9%