Falhas do tipo CWE-20

5.429 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-16421HIGHInappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code insideEPSS 0.5%CVE-2022-39016HIGHJavascript injection in PDFtron in M-Files HubshareEPSS 0.5%CVE-2024-21627HIGHSome attribute not escaped in Validate::isCleanHTML methodEPSS 0.5%CVE-2026-33936MEDIUMpython-ecdsa: Denial of Service via improper DER length validation in crafted private keysEPSS 0.5%CVE-2026-54405HIGHA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to EPSS 0.5%CVE-2026-16632MEDIUMboazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validationEPSS 0.5%CVE-2026-22547CRITICALGitea repository creation accepts invalid field valuesEPSS 0.5%CVE-2026-3641MEDIUMAppmax <= 1.0.3 - Missing Authorization to Order Status Manipulation and Arbitrary Order Creation via Webhook EndpointEPSS 0.5%CVE-2026-67296HIGHFreeRDP before 3.29.0 Denial of Service via RDPEI PDUEPSS 0.5%CVE-2023-21515HIGHInstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to exEPSS 0.5%CVE-2026-27959HIGHKoa has Host Header Injection via `ctx.hostname`EPSS 0.5%CVE-2026-24512HIGHingress-nginx auth-method nginx configuration injectionEPSS 0.5%CVE-2023-21514HIGHImproper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API toEPSS 0.5%CVE-2022-39012HIGHHuawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application servEPSS 0.5%CVE-2026-54208HIGHTeamDavid: Arbitrary File Write leading to Stored XSSEPSS 0.5%CVE-2023-6835MEDIUMMultiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating couldEPSS 0.5%CVE-2023-35306MEDIUMMicrosoft PostScript and PCL6 Class Printer Driver Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-71399HIGHBetter Auth before 1.4.5 Path Normalization Bypass via rou3EPSS 0.5%CVE-2023-39191HIGHKernel: ebpf: insufficient stack type checks in dynptrEPSS 0.5%CVE-2021-28547HIGHAdobe Creative Cloud for macOS Privilege Escalation VulnerabilityEPSS 0.5%