Falhas do tipo CWE-20

5.421 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-54909MEDIUMPion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attributeEPSS 0.6%CVE-2026-5329HIGHRapid7 Velociraptor Improper Input Validation in Client Message HandlerEPSS 0.6%CVE-2026-56340HIGHvLLM - Denial of Service via Unvalidated Multimodal EmbeddingsEPSS 0.6%CVE-2023-5571MEDIUMImproper Input Validation in vriteio/vriteEPSS 0.6%CVE-2026-7803CRITICALFlow Validation Bypass via Empty Component Type FieldEPSS 0.6%CVE-2019-1746HIGHCisco IOS and IOS XE Software Cluster Management Protocol Denial of Service VulnerabilityEPSS 0.6%CVE-2026-1315HIGHUnauthenticated Denial of Service via Firmware Update Endpoint on TP-Link Tapo C220 & C520WSEPSS 0.6%CVE-2019-1816MEDIUMCisco Web Security Appliance Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-53652HIGHJenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches oEPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%CVE-2022-3676MEDIUMIn Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of tEPSS 0.6%CVE-2026-93295HIGHMISP Background Job Argument Injection via Console Path Switches Enables Remote Code ExecutionEPSS 0.6%CVE-2026-39386HIGHNeko has Self-service Privilege Escalation for Authenticated UsersEPSS 0.6%CVE-2023-31013MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploiEPSS 0.6%CVE-2023-31012MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploitEPSS 0.6%CVE-2024-21315HIGHMicrosoft Defender for Endpoint Protection Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2020-3390HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Trap Denial of Service VulnerabilityEPSS 0.6%CVE-2025-61920HIGHAuthlib is vulnerable to Denial of Service via Oversized JOSE SegmentsEPSS 0.6%CVE-2023-48311HIGHAny image allowed by defaultEPSS 0.6%CVE-2023-28113MEDIUMrussh may use insecure Diffie-Hellman keysEPSS 0.6%