Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-55993HIGHApache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviourEPSS 0.9%CVE-2024-44808CRITICALAn issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.EPSS 0.9%CVE-2026-46726HIGHApache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headersEPSS 0.9%CVE-2025-0465MEDIUMAquilaCMS categories deserializationEPSS 0.9%CVE-2023-45163CRITICAL1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code executionEPSS 0.9%CVE-2018-0475—Cisco IOS and IOS XE Software Cluster Management Protocol Denial of Service VulnerabilityEPSS 0.9%CVE-2018-1070MEDIUMrouting before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire sEPSS 0.9%CVE-2023-39530MEDIUMPrestaShop vulnerable to file deletion via CustomerMessageEPSS 0.9%CVE-2022-47392MEDIUMCODESYS: Multiple products prone to Improper Input ValidationEPSS 0.9%CVE-2024-31212MEDIUMSQL injection in index_chart_data actionEPSS 0.9%CVE-2022-47189HIGHDoS via file upload vulnerability at Generex CS141EPSS 0.9%CVE-2026-92860CRITICALrcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validationEPSS 0.9%CVE-2020-11007MEDIUMNegative charge in shopping cart possible in ShopizerEPSS 0.9%CVE-2025-24499HIGHA vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0EPSS 0.9%CVE-2025-29847HIGHApache Linkis: Arbitrary File Read via Double URL Encoding BypassEPSS 0.9%CVE-2025-69288CRITICALTitra has Remote Code Execution in Admin FunctionalityEPSS 0.9%CVE-2020-15200MEDIUMSegfault in TensorflowEPSS 0.9%CVE-2024-38105MEDIUMWindows Layer-2 Bridge Network Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2024-25016HIGHIBM MQ denial of serviceEPSS 0.8%CVE-2023-30991HIGHIBM Db2 denial of serviceEPSS 0.8%