Fallos del tipo CWE-20

5421 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2021-21533MEDIUMWyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in thEPSS 0.8%CVE-2023-5397HIGHServer receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failEPSS 0.8%CVE-2023-5104MEDIUMImproper Input Validation in nocodb/nocodbEPSS 0.8%CVE-2022-29922HIGHA vulnerability exists in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server. The vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS ...EPSS 0.8%CVE-2024-29946HIGHRisky command safeguards bypass in Dashboard Examples HubEPSS 0.8%CVE-2019-19164HIGHDext5 Upload ActiveX Arbitrary File Execution VulnerabilityEPSS 0.8%CVE-2021-38455HIGHAUVESY VersiondogEPSS 0.8%CVE-2025-2296HIGHUn-verified kernel bypass Secure Boot mechanism in direct boot modeEPSS 0.8%CVE-2022-22726—A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users thEPSS 0.8%CVE-2023-29353MEDIUMSysinternals Process Monitor for Windows Denial of Service VulnerabilityEPSS 0.8%CVE-2026-32622HIGHSQLBot: Remote Code Execution via Terminology PoisoningEPSS 0.8%CVE-2023-47355HIGHThe com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for EPSS 0.8%CVE-2026-8751MEDIUMh2oai h2o-3 JAR Model.java importBinaryModel deserializationEPSS 0.8%CVE-2026-93568HIGHIo.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connect requests are downgraded as regular connect requestsEPSS 0.8%CVE-2026-23571MEDIUMCommand Injection in 1E-Nomad-RunPkgStatusRequest Instruction in TeamViewer DEXEPSS 0.8%CVE-2018-19010—Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. AEPSS 0.8%CVE-2024-41976HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.8%CVE-2024-38879HIGHA vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), OmniviEPSS 0.8%CVE-2018-12448—Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-htEPSS 0.8%CVE-2026-32604CRITICALSpinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and pathsEPSS 0.8%