Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-58186HIGHApache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responsesEPSS 0.7%CVE-2023-35944HIGHEnvoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemesEPSS 0.7%CVE-2020-3257HIGHCisco IOx Application Environment for IOS Software for Cisco Industrial Routers VulnerabilitiesEPSS 0.7%CVE-2025-59032HIGHManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedEPSS 0.7%CVE-2022-34844MEDIUMBIG-IP and BIG-IQ AWS vulnerability CVE-2022-34844EPSS 0.7%CVE-2026-82550MEDIUMLinux Foundation Magma NGSetupRequest input validationEPSS 0.7%CVE-2025-58173HIGHFreshRSS vulnerable to authenticated RCE via path traversal inside include()EPSS 0.7%CVE-2022-36082MEDIUMmangadex-downloader vulnerable to unauthorized file readingEPSS 0.7%CVE-2024-32371HIGHAn issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain aEPSS 0.7%CVE-2020-3507HIGHCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Remote Code Execution and Denial of Service VulnerabilitiesEPSS 0.7%CVE-2022-34476CRITICALASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulneraEPSS 0.7%CVE-2024-25590HIGHCrafted responses can lead to a denial of service due to cache inefficiencies in the RecursorEPSS 0.7%CVE-2023-49568HIGHMaliciously crafted Git server replies can cause DoS on go-git clientsEPSS 0.7%CVE-2023-41303—Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in EPSS 0.7%CVE-2023-46159LOWIBM Storage Ceph denial of serviceEPSS 0.7%CVE-2020-16216—Philips Patient Monitoring Devices Improper Input ValidationEPSS 0.7%CVE-2026-43777HIGHThis issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6.EPSS 0.7%CVE-2025-6563MEDIUMCross-site scripting via dst parameter in RouterOS WiFi hotspotEPSS 0.7%CVE-2022-23831HIGHInsufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential WindEPSS 0.7%CVE-2026-43692HIGHA validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.7%