Falhas do tipo CWE-20

5.428 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-12128MEDIUMPinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' ParameterEPSS 0.6%CVE-2023-22491HIGHgatsby-transformer-remark vulnerable to unsanitized JavaScript code injection EPSS 0.6%CVE-2026-24406HIGHiccDEV has Heap Buffer Overflow in CIccTagNamedColor2::SetSize()EPSS 0.6%CVE-2026-24412HIGHiccDEV has Heap Buffer Overflow in icCurvesFromXml()EPSS 0.6%CVE-2025-27489HIGHAzure Local Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-24405HIGHiccDEV has Heap Buffer Overflow in CIccMpeCalculator::Read()EPSS 0.6%CVE-2022-45770HIGHImproper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.EPSS 0.6%CVE-2025-48490MEDIUMLaravel Rest Api has a Search Validation BypassEPSS 0.6%CVE-2024-28226HIGHFs has an improper input validation vulnerabilityEPSS 0.6%CVE-2022-23766HIGHBigFileAgent arbitrary file execution vulnerabilityEPSS 0.6%CVE-2023-36719HIGHMicrosoft Speech Application Programming Interface (SAPI) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-4287HIGHImproper Input Validation in mintplex-labs/anything-llmEPSS 0.6%CVE-2026-37460HIGHMissing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cauEPSS 0.6%CVE-2023-27984HIGHA CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to rEPSS 0.6%CVE-2026-49098MEDIUMApache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topicEPSS 0.6%CVE-2025-60938HIGHEmoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitraryEPSS 0.6%CVE-2021-27418MEDIUMGE UR family input validationEPSS 0.6%CVE-2026-59724HIGHSocket.IO: Engine.IO WebTransport SID DoSEPSS 0.6%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.6%CVE-2024-27092MEDIUMContent spoofing - real Hoppscotch emailsEPSS 0.6%