Weaknesses of type CWE-670

110 results

Validação inadequada de entrada

A aplicação aceita dados do usuário sem verificar se estão no formato, tamanho ou tipo esperado, permitindo que valores malformados ou maliciosos sejam processados. Isso abre porta para injeção, estouro de buffer, lógica corrompida e outros ataques.

Example

Um formulário web que recebe um CPF sem verificar se contém apenas dígitos, ou que aceita um campo 'idade' como string sem validar se é um número positivo. Um atacante envia valores inesperados (SQL injection, scripts) que a aplicação processa como legítimos.

How to mitigate

Implemente validação em todos os pontos de entrada: whitelist de caracteres permitidos, limites de tamanho, tipagem explícita, e rejeite dados que não correspondam ao esperado. Valide tanto no cliente (UX) quanto no servidor (segurança).

CVE-2023-0400MEDIUM The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP contEPSS 0.4%CVE-2026-48844HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could leaEPSS 0.4%CVE-2024-45298MEDIUMDisabled user can bypass lockout by requesting password reset in wiki.jsEPSS 0.4%CVE-2026-32713MEDIUMPX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File DescriptorsEPSS 0.4%CVE-2026-40719HIGHDeadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolvEPSS 0.4%CVE-2026-56307MEDIUMCap-go - Broken Cursor Pagination in /private/devices EndpointEPSS 0.4%CVE-2026-16392CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2026-34946MEDIUMWasmtime's host panics when Winch compiler executes `table.fill`EPSS 0.4%CVE-2022-41884MEDIUMSeg fault in `ndarray_tensor_bridge` due to zero and large inputs in TensorflowEPSS 0.4%CVE-2026-56328HIGHCapgo - Integrity Issue in Release Routing via Multiple Public ChannelsEPSS 0.3%CVE-2026-40396MEDIUMVarnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could sEPSS 0.3%CVE-2026-33011HIGHNest Fastify HEAD Request Middleware BypassEPSS 0.3%CVE-2024-35195MEDIUMRequests `Session` object does not verify requests after making first request with verify=FalseEPSS 0.3%CVE-2024-47168LOWThe `enable_monitoring` flag set to `False` does not disable monitoring in GradioEPSS 0.3%CVE-2026-7656HIGHBroken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stackEPSS 0.3%CVE-2026-26267HIGHrs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collideEPSS 0.3%CVE-2025-2886MEDIUMTerminating targets role delegations are not respected in toughEPSS 0.3%CVE-2025-24800CRITICALCritical vulnerability in `ismp-grandpa` <v15.0.1EPSS 0.3%CVE-2024-5659HIGHRockwell Automation Multicast Request Causes major nonrecoverable fault on Select ControllersEPSS 0.3%CVE-2026-6608MEDIUMlm-sys fastchat Arena Side-by-Side View add_text control flowEPSS 0.3%