Fallos del tipo CWE-20

5421 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-52802HIGHRIOT-OS missing dhcpv6_opt_t minimum header length checkEPSS 0.8%CVE-2023-27496MEDIUMEnvoy may crash when a redirect url without a state param is received in the oauth filterEPSS 0.8%CVE-2023-48608LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.8%CVE-2021-25444—An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.EPSS 0.8%CVE-2022-4032HIGHQuiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short AnswerEPSS 0.8%CVE-2022-31772MEDIUMIBM MQ denial of serviceEPSS 0.8%CVE-2023-36406MEDIUMWindows Hyper-V Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-32728MEDIUMCode injection in zabbix_agent2 smart.disk.get caused by smartctl pluginEPSS 0.8%CVE-2026-45062HIGHFrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP FilesEPSS 0.8%CVE-2026-44300HIGHOpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/InjectionEPSS 0.8%CVE-2022-3767HIGHMissing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every EPSS 0.8%CVE-2024-25090MEDIUMApache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users modeEPSS 0.8%CVE-2016-9494—Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation, potentially leading to denial of serviceEPSS 0.8%CVE-2025-26413HIGHApache Kvrocks: The server was crashed by the negative offsetEPSS 0.8%CVE-2026-53503HIGHThumbor convolution filter allows divide-by-zero in C extension leading to remote DoSEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2026-93567HIGHIo.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authorityEPSS 0.7%CVE-2025-62222HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-29507MEDIUMdlt-daemon could crash if there is special character in dlt.confEPSS 0.7%CVE-2022-29562LOWA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 0.7%