Falhas do tipo CWE-20

5.439 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-54694CRITICALNationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account TakeoverEPSS 0.5%CVE-2025-54247MEDIUMAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2021-25738MEDIUMCode exec via yaml parsingEPSS 0.5%CVE-2025-62455HIGHMicrosoft Message Queuing (MSMQ) Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-51017HIGHPocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin DataEPSS 0.5%CVE-2021-35268MEDIUMIn NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow EPSS 0.5%CVE-2022-41888MEDIUMUnckecked rank size in `tf.image.generate_bounding_box_proposals` in TensorflowEPSS 0.5%CVE-2026-56151MEDIUMImproper Input Validation in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2025-52569MEDIUMGitHub.jl lacks validation for user-provided fieldsEPSS 0.5%CVE-2026-26063HIGHCediPay Affected by Improper Input Validation in Payment ProcessingEPSS 0.5%CVE-2026-56349MEDIUMn8n - Guardrail Node Bypass via Crafted InputEPSS 0.5%CVE-2025-50233MEDIUMA vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of tEPSS 0.5%CVE-2026-9212MEDIUMInsufficient authentication and input validation in certain NETGEAR productsEPSS 0.5%CVE-2026-30077HIGHOpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistEPSS 0.5%CVE-2025-50178MEDIUMGitForge.jl lacks validation for user provided fieldsEPSS 0.5%CVE-2026-63734MEDIUMSurrealDB before 3.2.0 Denial of Service via malformed SurrealML importEPSS 0.5%CVE-2025-58175MEDIUMGeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity ResolutionEPSS 0.5%CVE-2025-21370HIGHWindows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-47931HIGHColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2024-9348HIGHDocker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build viewEPSS 0.5%