Falhas do tipo CWE-20

5.429 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-81662HIGHFlowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configuration KeysEPSS 0.5%CVE-2022-41909MEDIUMSegfault in `CompositeTensorVariantToComponents` in TensorflowEPSS 0.5%CVE-2021-36402MEDIUMIn Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.EPSS 0.5%CVE-2024-9507MEDIUMContact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.15.2 - Authenticated (Administrator+) Improper Input Validation via iconUpload Function to Arbitrary File ReadEPSS 0.5%CVE-2026-67974HIGHA parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackerEPSS 0.5%CVE-2026-11386CRITICALubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code ExecutionEPSS 0.5%CVE-2026-2996HIGHAdvanced Product Fields (Product Addons) for WooCommerce <= 1.6.21 - Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST RequestEPSS 0.5%CVE-2025-52568HIGHNeKernal Multiple Memory Corruption Vulnerabilities in mkfs.hefsEPSS 0.5%CVE-2019-1918HIGHCisco IOS XR Software Intermediate System–to–Intermediate System Denial of Service VulnerabilityEPSS 0.5%CVE-2022-32243—When a user opens manipulated Scalable Vector Graphics (.svg, svg.x3d) files received from untrusted sources in SAP 3D Visual Enterprise VieEPSS 0.5%CVE-2022-32235—When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer,EPSS 0.5%CVE-2026-59881MEDIUMAIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflateEPSS 0.5%CVE-2026-21282MEDIUMAdobe Commerce | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2022-35171—When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the appliEPSS 0.5%CVE-2026-15724HIGHPath traversal in Progress ShareFile Storage Zones Controller (SZC)EPSS 0.5%CVE-2026-81633MEDIUMUnhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segmentEPSS 0.5%CVE-2022-39016HIGHJavascript injection in PDFtron in M-Files HubshareEPSS 0.5%CVE-2024-21627HIGHSome attribute not escaped in Validate::isCleanHTML methodEPSS 0.5%CVE-2024-27909MEDIUMA denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.EPSS 0.5%CVE-2026-25513HIGHFacturaScripts has SQL Injection vulnerability in API ORDER BY ClauseEPSS 0.5%