Falhas do tipo CWE-20

5.429 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2022-32240—When a user opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) files received from untrusted sources in SAP 3D Visual Enterprise ViewEPSS 0.6%CVE-2026-43793CRITICALAn issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS SEPSS 0.6%CVE-2022-32241—When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual EnterpriseEPSS 0.6%CVE-2022-32237—When a user opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) files received from untrusted sources in SAP 3D Visual EnterpriEPSS 0.6%CVE-2025-68667CRITICALConduit-derived homeservers are affected by a Confused Deputy and Improper Input Validation issueEPSS 0.6%CVE-2023-30542MEDIUMGovernorCompatibilityBravo may trim proposal calldataEPSS 0.6%CVE-2026-48922HIGHJenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, aEPSS 0.6%CVE-2026-47641MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-62917MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2025-27211HIGHAn Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with acEPSS 0.6%CVE-2018-0249—A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCAEPSS 0.6%CVE-2018-0307—A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an EPSS 0.6%CVE-2026-70607MEDIUMElectron: window.open features string controls some window options considered privilegedEPSS 0.6%CVE-2026-25117HIGHpwn.college DOJO vulnerable to sandbox escape leading to arbitrary javascript executionEPSS 0.6%CVE-2023-21559MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-21540MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-21550MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-35048CRITICALPiwigo RCE via PHP Code Injection into Config File in InstallerEPSS 0.6%CVE-2026-94379MEDIUMMISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP)EPSS 0.6%CVE-2026-42809CRITICALApache Polaris: staged table creation could vend storage credentials for unvalidated locationsEPSS 0.6%