Falhas do tipo CWE-20

5.429 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-1736MEDIUMStream HTTP wrapper header check might omit basic auth headerEPSS 0.5%CVE-2020-15731LOWLocal Privilege Escalation in Bitdefender Engines (VA-8953)EPSS 0.5%CVE-2020-3409HIGHCisco IOS and IOS XE Software PROFINET Denial of Service VulnerabilityEPSS 0.5%CVE-2025-5114MEDIUMeasysoft zentaopms Editor index.php edit deserializationEPSS 0.5%CVE-2026-44978MEDIUMxrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verificationEPSS 0.5%CVE-2026-51997HIGHAn issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functionsEPSS 0.5%CVE-2021-25489LOWAssuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format stEPSS 0.5%KEVCVE-2026-82008CRITICALAdobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2026-22102CRITICALArbitrary file overwrite through certificate update functionalityEPSS 0.5%CVE-2020-1633HIGHJunos OS: MX Series: Crafted packets traversing a Broadband Network Gateway (BNG) configured with IPv6 NDP proxy could lead to Denial of ServiceEPSS 0.5%CVE-2020-17393MEDIUMThis vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker mEPSS 0.5%CVE-2025-10769MEDIUMh2oai h2o-3 H2 JDBC Driver ImportSQLTable deserializationEPSS 0.5%CVE-2026-2750CRITICALCommand Injection via CLAPI generatetrapsEPSS 0.5%CVE-2026-53412CRITICALZoom Workplace VDI Plugin for Windows - Improper Input ValidationEPSS 0.5%CVE-2022-34159HIGHHuawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device service exceptions.EPSS 0.5%CVE-2026-35081HIGHArbitrary process termination vulnerability in method ugw-logstopEPSS 0.5%CVE-2025-20146HIGHCisco IOS XR Software for ASR 9000 Series Routers Layer 3 Multicast Routing Denial of Service VulnerabilityEPSS 0.5%CVE-2026-32735LOWUnpacking Arbitrary Mustache Template Files via `maven-dependency-plugin`EPSS 0.5%CVE-2026-54254MEDIUMCyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sitesEPSS 0.5%CVE-2018-14656HIGHA missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel memory at an arbitrarEPSS 0.5%