Falhas do tipo CWE-20

5.439 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2021-0267HIGHJunos OS: Receipt of a crafted DHCP packet will cause the jdhcpd DHCP service to core.EPSS 0.5%CVE-2026-26143HIGHMicrosoft PowerShell Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2025-1088LOWVery long unicode dashboard title or panel name can hang the frontendEPSS 0.5%CVE-2022-38985HIGHThe facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidenEPSS 0.5%CVE-2024-25656MEDIUMImproper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer PremisEPSS 0.5%CVE-2023-23409MEDIUMClient Server Run-Time Subsystem (CSRSS) Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-76711HIGHUnauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.5%CVE-2023-32463LOW Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A remote unauthenticateEPSS 0.5%CVE-2022-41891MEDIUMSegfault in `tf.raw_ops.TensorListConcat` in TensorflowEPSS 0.5%CVE-2025-5878MEDIUMESAPI esapi-java-legacy SQL Injection Defense Encoder.encodeForSQL special elementEPSS 0.5%CVE-2025-6547CRITICALOn Node.js < 3, pbkdf2 silently disregards Uint8Array input, returning static keysEPSS 0.5%CVE-2025-1022HIGHVersions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by BrowEPSS 0.5%CVE-2026-76035CRITICALInappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary codeEPSS 0.5%CVE-2026-78900CRITICALImproper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code oEPSS 0.5%CVE-2026-57130HIGHPraisonAI: IMAP Command Injection via Unsanitized Email Search ParametersEPSS 0.5%CVE-2025-34157CRITICALCoolify Stored Cross-Site Scripting (XSS) in Project Name FieldEPSS 0.5%CVE-2026-79111CRITICALImproper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code ouEPSS 0.5%CVE-2026-85047CRITICALImproper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentiallEPSS 0.5%CVE-2024-30110LOWLack of input validation vulnerability affects DRYiCE AEX v10EPSS 0.5%CVE-2026-24404HIGHiccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()EPSS 0.5%