Fallos del tipo CWE-20

5418 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2023-33182NONENextcloud Contacts photos only sanitized if mime type is all lower caseEPSS 0.8%CVE-2023-0100—In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTEPSS 0.8%CVE-2025-10155CRITICALPickleScan Security Bypass Using Misleading File ExtensionEPSS 0.8%CVE-2026-42579HIGHNetty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)EPSS 0.8%CVE-2025-21194HIGHMicrosoft Surface Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2024-45117HIGHAdobe Commerce | Improper Input Validation (CWE-20)EPSS 0.8%CVE-2024-47823HIGHLivewire Remote Code Execution (RCE) on File UploadsEPSS 0.8%CVE-2025-52907HIGHTOTOLINK X6000R Security Bypass VulnerabilityEPSS 0.8%CVE-2022-22658MEDIUMAn input validation issue was addressed with improved input validation. This issue is fixed in iOS 16.0.3. Processing a maliciously crafted EPSS 0.8%CVE-2024-21625HIGHOne-click remote code execution via malicious deep linkEPSS 0.8%CVE-2023-22465HIGHHttp4s has fatal error parsing User-Agent and Server headersEPSS 0.8%CVE-2026-33218HIGHNATS has pre-auth server panic via leafnode handlingEPSS 0.8%CVE-2022-40227HIGHA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP MobEPSS 0.8%CVE-2021-3048MEDIUMPAN-OS: Invalid URLs in an External Dynamic List (EDL) can Lead to Firewall OutageEPSS 0.8%CVE-2025-21344HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 0.8%CVE-2017-6794—A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injeEPSS 0.8%CVE-2020-15234MEDIUMRedirect URL matching ignores character casingEPSS 0.8%CVE-2023-36762HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.8%CVE-2023-38495HIGHCrossplane vulnerable to possible image tampering from missing image validation for PackagesEPSS 0.8%CVE-2021-3802—A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highEPSS 0.8%