Falhas do tipo CWE-20

5.430 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-0841MEDIUMAridius XYZ News loadMore deserializationEPSS 0.5%CVE-2023-49796MEDIUMMindsDB Arbitrary File Write vulnerabilityEPSS 0.5%CVE-2026-84469HIGHfastify vulnerable to request validation bypass via skipped boolean false schemasEPSS 0.5%CVE-2025-6444MEDIUMServiceStack GetErrorResponse Improper Input Validation NTLM Relay VulnerabilityEPSS 0.5%CVE-2024-7974HIGHInsufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruptEPSS 0.5%CVE-2026-47928CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2023-7060HIGHMissing Security Control in Zephyr OS IP Packet HandlingEPSS 0.5%CVE-2026-48284CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2024-39950HIGHA vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities toEPSS 0.5%CVE-2026-54205MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionalityEPSS 0.5%CVE-2026-54206MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionalityEPSS 0.5%CVE-2026-54207MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionalityEPSS 0.5%CVE-2022-34436LOW Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuraEPSS 0.5%CVE-2024-27931MEDIUMInsufficient permission checking in `Deno.makeTemp*` APIsEPSS 0.5%CVE-2022-34885HIGHAn improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbEPSS 0.5%CVE-2025-59952HIGHminio-java Client XML Tag is Vulnerable to Value SubstitutionEPSS 0.5%CVE-2026-59354CRITICALSpring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadataEPSS 0.5%CVE-2023-35163MEDIUMVega's validators able to submit duplicate transactions EPSS 0.5%CVE-2021-3442—A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripEPSS 0.5%CVE-2018-15431—Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution VulnerabilitiesEPSS 0.5%