Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2023-27488MEDIUMEnvoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.EPSS 0.7%CVE-2024-3029CRITICALImproper Input Validation in mintplex-labs/anything-llmEPSS 0.7%CVE-2026-22444HIGHApache Solr: Insufficient file-access checking in standalone core-creation requestsEPSS 0.7%CVE-2025-2622MEDIUMaizuda snail-job Workflow-Task Management Module check-node-expression getRuntime deserializationEPSS 0.7%CVE-2026-48769CRITICALIncus has an arbitrary file write on its client due to trusted image hashEPSS 0.7%CVE-2022-32236—When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the apEPSS 0.7%CVE-2024-26253MEDIUMWindows rndismp6.sys Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-3841HIGHInsufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTMLEPSS 0.7%CVE-2021-42117LOWUI Redressing in TopEaseEPSS 0.7%CVE-2019-15997MEDIUMCisco DNA Spaces: Connector Command Injection VulnerabilityEPSS 0.7%CVE-2025-4377HIGHPath traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.phpEPSS 0.7%CVE-2022-29492MEDIUMA vulnerability exists in the handling of a malformed IEC 104 TCP packet. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TCP connection is left open. This may cause a denial-of-service if the affected conne ...EPSS 0.7%CVE-2022-22508MEDIUMCODESYS V3: Improper Input ValidationEPSS 0.7%CVE-2023-24493MEDIUMA formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An auEPSS 0.7%CVE-2023-32305HIGHaiven-extras PostgreSQL Privilege Escalation Through Overloaded Search PathEPSS 0.7%CVE-2021-27760MEDIUMHCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats loading script on restartEPSS 0.7%CVE-2022-27674HIGHInsufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to aEPSS 0.7%CVE-2024-22027MEDIUMImproper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a EPSS 0.7%CVE-2020-3429HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WPA Denial of Service VulnerabilityEPSS 0.7%CVE-2020-15197MEDIUMDenial of Service in TensorflowEPSS 0.7%