Fallos del tipo CWE-20

5421 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-38055MEDIUMMicrosoft Windows Codecs Library Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-45558CRITICALRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section saveEPSS 0.8%CVE-2026-21279HIGHColdFusion | Improper Input Validation (CWE-20)EPSS 0.8%CVE-2018-0395HIGHCisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service VulnerabilityEPSS 0.8%CVE-2024-23655HIGHAttacker can prevent users from accessing received emailsEPSS 0.8%CVE-2022-31041HIGHInsufficient content-type validation for uploaded files in open-formsEPSS 0.8%CVE-2026-27282HIGHColdFusion | Improper Input Validation (CWE-20)EPSS 0.8%CVE-2021-25255HIGHYandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.EPSS 0.8%CVE-2024-41120CRITICALstreamlit-geospatial blind SSRF in pages/9_🔲_Vector_Data_Visualization.pyEPSS 0.8%CVE-2023-25533HIGHNVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A successful exploit of tEPSS 0.8%CVE-2024-6239HIGHPoppler: pdfinfo: crash in broken documents when using -dests parameterEPSS 0.8%CVE-2026-59878HIGHApache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoSEPSS 0.8%CVE-2023-42448HIGHHydra's contestation period in head datum can be modified during Close transaction, allowing malicious participant to freely modify the contestation deadlineEPSS 0.8%CVE-2026-49432HIGHApache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of serviceEPSS 0.8%CVE-2021-39220LOWBypass of image blocking in Nextcloud MailEPSS 0.8%CVE-2023-29451MEDIUMDenial of service caused by a bug in the JSON parserEPSS 0.8%CVE-2023-38728MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-29194MEDIUMvitess allows users to create keyspaces that can deny access to already existing keyspacesEPSS 0.8%CVE-2023-38740MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-30987MEDIUMIBM Db2 denial of serviceEPSS 0.8%