Falhas do tipo CWE-20

5.430 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2020-3489HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service VulnerabilitiesEPSS 0.5%CVE-2026-34445HIGHONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.EPSS 0.5%CVE-2024-22117LOWValue of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is addedEPSS 0.5%CVE-2024-43115HIGHApache DolphinScheduler: Alert Script AttackEPSS 0.5%CVE-2025-9287CRITICALMissing type checks leading to hash rewind and passing on crafted dataEPSS 0.5%CVE-2018-0235—A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjaEPSS 0.5%CVE-2026-1580HIGHingress-nginx auth-method nginx configuration injectionEPSS 0.5%CVE-2021-33110MEDIUMImproper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windows 10 and 11 before EPSS 0.5%CVE-2026-45783HIGHlibp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodesEPSS 0.5%CVE-2026-50370HIGHDHCP Server Service Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-49774HIGHModuleScanner flaws in SuiteCRMEPSS 0.5%CVE-2025-31995LOWHCL Unica MaxAI Workbench is vulnerable to improper input validationEPSS 0.5%CVE-2025-59190MEDIUMWindows Search Service Denial of Service VulnerabilityEPSS 0.5%CVE-2026-29909MEDIUMMRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpointEPSS 0.5%CVE-2026-4755CRITICALCWE-20 in MolotovCherry Android-ImageMagick7EPSS 0.5%CVE-2024-7507HIGHRockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix® 5380 Controller Denial-of-Service Vulnerability via Input ValidationEPSS 0.5%CVE-2018-14799—In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize datEPSS 0.5%CVE-2026-40712CRITICALDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high prEPSS 0.5%CVE-2026-46738CRITICALDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high prEPSS 0.5%CVE-2026-40714HIGHDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attackeEPSS 0.5%