Falhas do tipo CWE-20

5.429 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-1026HIGHVersions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through tEPSS 0.5%CVE-2024-23669MEDIUMAn improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2EPSS 0.5%CVE-2025-34123HIGHVideoCharge Studio 2.12.3.685 SEH Buffer Overflow via .VSC FileEPSS 0.5%CVE-2024-27912HIGHA denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending EPSS 0.5%CVE-2024-32992HIGHInsufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.5%CVE-2024-56321LOWGoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host accessEPSS 0.5%CVE-2022-41921LOWDiscourse chat messages should have a maximum character limitEPSS 0.5%CVE-2021-33146MEDIUMImproper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unautEPSS 0.5%CVE-2025-55173MEDIUMNext.js Content Injection Vulnerability for Image OptimizationEPSS 0.5%CVE-2026-16520HIGHImproper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians GeniaEPSS 0.5%CVE-2025-12275CRITICALMail Configuration File Manipulation + Command ExecutionEPSS 0.5%CVE-2026-78009HIGHFireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS)EPSS 0.5%CVE-2018-4843MEDIUMA vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All EPSS 0.5%CVE-2026-54588CRITICALPoweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.EPSS 0.5%CVE-2023-31161MEDIUMImproper Input Validation in Web InterfaceEPSS 0.5%CVE-2025-2855MEDIUMelunez eladmin upload checkFile deserializationEPSS 0.5%CVE-2026-26062HIGHFleet server may terminate unexpectedly when handling certain gRPC requestsEPSS 0.5%CVE-2025-26358MEDIUMA CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an EPSS 0.5%CVE-2025-3413MEDIUMopplus springboot-admin SysGeneratorController.java code deserializationEPSS 0.5%CVE-2024-12994MEDIUMrunning-elephant Datart File Upload import extractModel deserializationEPSS 0.5%