Fallos del tipo CWE-20

5423 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2022-29562LOWA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 0.7%CVE-2025-43342CRITICALA correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, maEPSS 0.7%CVE-2025-43253CRITICALThis issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app mayEPSS 0.7%CVE-2026-7755HIGHMCP Server Configuration Validator Bypass via File Upload APIEPSS 0.7%CVE-2017-3873—A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight AcEPSS 0.7%CVE-2022-29613—Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee numbEPSS 0.7%CVE-2026-45721CRITICALAlgernon: handler.lua discovery walks parent directories above the server rootEPSS 0.7%CVE-2024-21507MEDIUMVersions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cacEPSS 0.7%CVE-2025-34060CRITICALMonero Forum Remote Code Execution via Arbitrary File Read and Cookie ForgeryEPSS 0.7%CVE-2025-57644CRITICALAccela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative useEPSS 0.7%CVE-2024-42516HIGHApache HTTP Server: HTTP response splittingEPSS 0.7%CVE-2019-14905HIGHA vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in AnsibEPSS 0.7%CVE-2022-43863MEDIUMIBM QRadar SIEM privilege escalationEPSS 0.7%CVE-2025-11938MEDIUMChurchCRM setup.php deserializationEPSS 0.7%CVE-2020-15210MEDIUMSegmentation fault in tensorflow-liteEPSS 0.7%CVE-2022-43929MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.7%CVE-2026-56140CRITICALApache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling componentsEPSS 0.7%CVE-2026-65637CRITICALApache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incompleteEPSS 0.7%CVE-2023-27597HIGHOpenSIPS has vulnerability in the parse_uri() functionEPSS 0.7%CVE-2023-47746MEDIUMIBM Db2 denial of serviceEPSS 0.7%