Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2019-13939HIGHA vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3),EPSS 0.7%CVE-2022-4427MEDIUMSQL Injection via OTRS Search APIEPSS 0.7%CVE-2026-44180CRITICALJupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be BypassedEPSS 0.7%CVE-2023-41268MEDIUMPossible stack overflow due to insufficient input validationEPSS 0.7%CVE-2022-21696MEDIUMUsername spoofing in OnionShareEPSS 0.7%CVE-2022-41733MEDIUMIBM InfoSphere Information Server denial of serviceEPSS 0.7%CVE-2023-39529MEDIUMPrestaShop vulnerable to file deletion via attachment APIEPSS 0.7%CVE-2019-1750HIGHCisco IOS XE Software Catalyst 4500 Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.7%CVE-2026-3288HIGHingress-nginx rewrite-target nginx configuration injectionEPSS 0.7%CVE-2021-44462HIGHHorner Automation Cscape EnvisionRV Improper Input ValidationEPSS 0.7%CVE-2023-32690MEDIUMResponder can Invoke Undefined Behavior in libspdm RequesterEPSS 0.7%CVE-2022-43908MEDIUMIBM Security Guardium denial of serviceEPSS 0.7%CVE-2023-22581CRITICALWhite Rabbit Switch - Unauthenticated remote code executionEPSS 0.7%CVE-2022-43903MEDIUMIBM Security Guardium denial of serviceEPSS 0.7%CVE-2025-47282CRITICALMalicious google credential in DNS secret can lead to privilege escalationEPSS 0.7%CVE-2023-38131MEDIUMImproper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via neEPSS 0.7%CVE-2023-41917CRITICALImproper input validation in Kiloview P1/P2 devices allows for remote code executionEPSS 0.7%CVE-2023-32485CRITICAL Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attackEPSS 0.7%CVE-2014-125114HIGHi-Ftp 2.20 Schedule.xml Stack-Based Buffer OverflowEPSS 0.7%CVE-2022-43919MEDIUMIBM MQ denial of serviceEPSS 0.7%