Fallos del tipo CWE-20

5421 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-32604CRITICALSpinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and pathsEPSS 0.8%CVE-2022-31170HIGH OpenZeppelin Contracts's ERC165Checker may revert instead of returning falseEPSS 0.8%CVE-2022-36027MEDIUMSegfault TFLite converter on per-channel quantized transposed convolutions in TensorFlowEPSS 0.8%CVE-2024-25131HIGHOpenshift-dedicated: must-gather-operator: yaml template injection leads to privilege escalationEPSS 0.8%CVE-2024-23641HIGHSending a GET or HEAD request with a body crashes SvelteKitEPSS 0.8%CVE-2025-54365HIGHfastapi-guard patch contains bypassable RegExEPSS 0.8%CVE-2023-46929HIGHAn issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:EPSS 0.8%CVE-2023-4043MEDIUMParsson DoS when parsing numbers from untrusted sourcesEPSS 0.8%CVE-2021-41250MEDIUMPresence of non-blacklisted URL bypasses all other filtersEPSS 0.8%CVE-2021-39230HIGHError in JPNS kernel of ButterEPSS 0.8%CVE-2023-32075MEDIUMPimcore vulnerable to Business Logic Errors in Customer automation rulesEPSS 0.8%CVE-2024-38243HIGHKernel Streaming Service Driver Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2017-3849—A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and CiEPSS 0.8%CVE-2022-33876MEDIUMMultiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.EPSS 0.8%CVE-2026-26314HIGHGo Ethereum affected by DoS via malicious p2p messageEPSS 0.8%CVE-2022-40923MEDIUMA vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (EPSS 0.8%CVE-2023-32890MEDIUMIn modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additioEPSS 0.8%CVE-2025-27737HIGHWindows Security Zone Mapping Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2022-39306MEDIUMGrafana contains Improper Input ValidationEPSS 0.8%CVE-2024-52802HIGHRIOT-OS missing dhcpv6_opt_t minimum header length checkEPSS 0.8%