Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-38046HIGHPowerShell Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-4428HIGHsupport_uri validation missing in WARP client for WindowsEPSS 0.7%CVE-2023-23375HIGHMicrosoft ODBC and OLE DB Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-2455MEDIUMRow security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases whEPSS 0.7%CVE-2024-23634MEDIUMGeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store APIEPSS 0.7%CVE-2021-25748HIGHIngress-nginx `path` sanitization can be bypassed with newline characterEPSS 0.7%CVE-2023-22916HIGHThe configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FEPSS 0.7%CVE-2023-31010MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vuEPSS 0.7%CVE-2025-1556MEDIUMwestboy CicadasCMS Template Management system deserializationEPSS 0.7%CVE-2025-7876MEDIUMMetasoft 美特软件 MetaCRM download.jsp AnalyzeParam deserializationEPSS 0.7%CVE-2026-33332MEDIUMNiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustionEPSS 0.7%CVE-2026-46587HIGHApache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted inputEPSS 0.7%CVE-2026-46588HIGHApache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted inputEPSS 0.7%CVE-2026-49042HIGHApache Camel: langchain4j-tools: filter tool argument headers against declared parametersEPSS 0.7%CVE-2026-57817HIGHApache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flowEPSS 0.7%CVE-2024-23246HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macEPSS 0.7%CVE-2025-4563LOWNodes can bypass dynamic resource allocation authorization checksEPSS 0.7%CVE-2021-33115HIGHImproper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation EPSS 0.7%CVE-2026-42810CRITICALApache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or table namesEPSS 0.7%CVE-2024-1019HIGHWAF bypass of the ModSecurity v3 release lineEPSS 0.7%