Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-26582HIGHPAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systoolEPSS 0.9%CVE-2020-15109MEDIUMAbility to change order address without triggering address validations in solidusEPSS 0.9%CVE-2022-39881MEDIUMImproper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to reEPSS 0.9%CVE-2021-40365HIGHAffected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a deniEPSS 0.9%CVE-2024-26173HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-29257MEDIUMElectron's AutoUpdater module fails to validate certain nested components of the bundleEPSS 0.9%CVE-2023-0359MEDIUMipv6: Missing ipv6 nullptr-check in handle_ra_inputEPSS 0.9%CVE-2024-55952HIGHDataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE VulnerabilityEPSS 0.9%CVE-2024-38311MEDIUMApache Traffic Server: Request smuggling via pipelining after a chunked message bodyEPSS 0.9%CVE-2025-43347CRITICALThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26,EPSS 0.9%CVE-2021-37707MEDIUMManipulation of product reviews via APIEPSS 0.9%CVE-2022-38778MEDIUMA flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a requEPSS 0.9%CVE-2024-45798CRITICALMultiple Poisoned Pipeline Execution (PPE) vulnerabilitiesEPSS 0.9%CVE-2020-1676HIGHJuniper Networks Mist Cloud UI: SAML authentication response handling vulnerability.EPSS 0.9%CVE-2022-4504HIGHImproper Input Validation in openemr/openemrEPSS 0.9%CVE-2022-26108—When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versionEPSS 0.9%CVE-2022-22537—When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise ViewerEPSS 0.9%CVE-2026-45505HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper BypassEPSS 0.9%CVE-2023-34317MEDIUMAn improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18EPSS 0.9%CVE-2023-40034HIGHRepositoty takeover in woodpecker-ciEPSS 0.9%