Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-47378MEDIUMCODESYS: Multiple products prone to Improper Input ValidationEPSS 0.9%CVE-2026-27953HIGHormar has a Pydantic Validation Bypass via Kwargs Injection in Model ConstructorEPSS 0.9%CVE-2023-28099MEDIUMOpenSIPS has vulnerability in the ds_is_in_list() functionEPSS 0.9%CVE-2023-28098MEDIUMOpenSIPS has vulnerability in the Digest Authentication ParserEPSS 0.9%CVE-2023-26125MEDIUMVersions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a sEPSS 0.9%CVE-2023-46285HIGHA vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIEPSS 0.9%CVE-2022-0550HIGHAuthenticated RCE on logo report upload in Guardian/CMC before 22.0.0EPSS 0.9%CVE-2021-3624—There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code mEPSS 0.9%CVE-2022-0551HIGHAuthenticated RCE on project configuration import in Guardian/CMC before 22.0.0EPSS 0.9%CVE-2022-28695HIGHOn F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versionEPSS 0.9%CVE-2023-37915HIGHMalformed PID_PROPERTY_LIST parameter in DATA submessage remotely crashes OpenDDSEPSS 0.9%CVE-2026-44417HIGHApache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)EPSS 0.9%CVE-2024-50557HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.9%CVE-2024-49087MEDIUMWindows Mobile Broadband Driver Information Disclosure VulnerabilityEPSS 0.9%CVE-2023-32688MEDIUMInvalid push request payload crashes Parse ServerEPSS 0.9%CVE-2020-15191MEDIUMUndefined behavior in TensorflowEPSS 0.9%CVE-2023-46289HIGHRockwell Automation FactoryTalk® View Site Edition Vulnerable to Improper Input ValidationEPSS 0.9%CVE-2021-3583—A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the tEPSS 0.9%CVE-2019-12699HIGHCisco FXOS Software and Firepower Threat Defense Software Command Injection VulnerabilitiesEPSS 0.9%CVE-2023-20103MEDIUMCisco Secure Network Analytics Remote Code Execution VulnerabilityEPSS 0.9%