Falhas do tipo CWE-20

5.429 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-54204HIGHTeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionalityEPSS 0.6%CVE-2023-0683HIGHA valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.EPSS 0.6%CVE-2023-33964HIGHmx-chain-go does not treat invalid transaction with wrong username correctlyEPSS 0.6%CVE-2025-6279MEDIUMUpsonic Pickle add_tool cloudpickle.loads deserializationEPSS 0.6%CVE-2020-15201MEDIUMHeap buffer overflow in TensorflowEPSS 0.6%CVE-2023-31011MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploitEPSS 0.6%CVE-2021-25684HIGHapport can be stalled by reading a FIFOEPSS 0.6%CVE-2024-20464HIGHA vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attackerEPSS 0.6%CVE-2026-3294HIGHAuthentication Logic Vulnerability on Multiple TP-Link Range ExtendersEPSS 0.6%CVE-2023-49252HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change withouEPSS 0.6%CVE-2026-29905MEDIUMKirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformedEPSS 0.6%CVE-2023-29457MEDIUMInsufficient validation of Action form input fieldsEPSS 0.6%CVE-2023-49095HIGHnexkey allows arbitrary users to impersonate any remote user due to missing signature validationEPSS 0.6%CVE-2014-5398—Schneider Electric Wonderware Input ValidationEPSS 0.6%CVE-2024-2199MEDIUM389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.cEPSS 0.6%CVE-2026-54133CRITICALjmespath.php has CompilerRuntime code injection via unescaped function namesEPSS 0.6%CVE-2024-40721HIGHCHANGING Information Technology TCBServiSign Windows Version - Improper Input ValidationEPSS 0.6%CVE-2025-66918HIGHedoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.EPSS 0.6%CVE-2026-19826MEDIUMalldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserializationEPSS 0.6%CVE-2026-75987MEDIUMSPLWare esProc SocketData.java ObjectInputStream.readUnshared deserializationEPSS 0.6%