Falhas do tipo CWE-20

5.429 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-21234HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2021-1383MEDIUMCisco IOS XE SD-WAN Software Parameter Injection VulnerabilitiesEPSS 0.6%CVE-2026-45556CRITICALRoxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`EPSS 0.6%CVE-2026-42812CRITICALApache Polaris: No protection on `write.metadata.path`EPSS 0.6%CVE-2024-35227HIGHDiscourse vulnerable to DoS through OneboxEPSS 0.6%CVE-2026-55068CRITICALfree5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpointsEPSS 0.6%CVE-2025-4613HIGHClient side RCE in Google Web Designer AppEPSS 0.6%CVE-2023-25650MEDIUMArbitrary File Download Vulnerability in ZTE ZXCLOUD iRAIEPSS 0.6%CVE-2023-32170MEDIUMUnified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service VulnerabilityEPSS 0.6%CVE-2026-63621MEDIUMApache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategyEPSS 0.6%CVE-2026-61794MEDIUMCapsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panicEPSS 0.6%CVE-2022-43455MEDIUMCVE-2022-43455EPSS 0.6%CVE-2023-22939HIGHSPL Command Safeguards Bypass via the ‘map’ SPL Command in Splunk EnterpriseEPSS 0.6%CVE-2025-22137CRITICALArbitrary File Overwrite via HTTP POST in Pingvin ShareEPSS 0.6%CVE-2026-5388CRITICALjusthtml before 1.15.0 Multiple Security IssuesEPSS 0.6%CVE-2026-81707CRITICALopenssl_encrypt before 1.4.9 ANSI Escape Injection via Identity EmailEPSS 0.6%CVE-2026-7808CRITICALjusthtml before 1.16.0 Multiple Security Issues via SanitizationEPSS 0.6%CVE-2023-29134HIGHAn issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.EPSS 0.6%CVE-2025-29811HIGHWindows Mobile Broadband Driver Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-23998MEDIUMImproper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in AEPSS 0.6%