Falhas do tipo CWE-20

5.432 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2018-15431—Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution VulnerabilitiesEPSS 0.5%CVE-2023-22963MEDIUMThe personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-9]$ regular expressiEPSS 0.5%CVE-2026-49830MEDIUMDSpace: ORE resource URI does not validate scheme for non-web resourcesEPSS 0.5%CVE-2022-24926MEDIUMImproper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victimEPSS 0.5%CVE-2026-48188CRITICALSQL Injection via MySQL Quote MethodEPSS 0.5%CVE-2026-13794HIGHInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker whEPSS 0.5%CVE-2025-5326MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 verifyToken deserializationEPSS 0.5%CVE-2026-62295HIGHHAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2024-37917HIGHPexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a EPSS 0.5%CVE-2026-62296HIGHHAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2026-38891HIGHAn improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cause a Denial of ServiEPSS 0.5%CVE-2026-42566HIGHMeshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failureEPSS 0.5%CVE-2026-36501HIGHAn issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.5%CVE-2022-31172HIGHOpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signersEPSS 0.5%CVE-2025-60012MEDIUMApache Livy: Restrict file accessEPSS 0.5%CVE-2026-61634NONERabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_maxEPSS 0.5%CVE-2026-40454HIGHApache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server dataEPSS 0.5%CVE-2024-7005HIGHInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.5%CVE-2026-26452HIGHccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when pEPSS 0.5%CVE-2025-8963MEDIUMjeecgboot JimuReport Data Large Screen Template testConnection deserializationEPSS 0.5%