Falhas do tipo CWE-20

5.439 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-24407HIGHiccDEV has Undefined Behavior in icSigCalcOp()EPSS 0.5%CVE-2026-24404HIGHiccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()EPSS 0.5%CVE-2026-55973HIGH'dns-error-reporting: yes' leads to stack buffer overflowEPSS 0.5%CVE-2026-48110HIGHRussh: SSH message fields were decoded through allocation-first parsers before field-specific boundsEPSS 0.5%CVE-2025-55679MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-51606HIGHAn improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminateEPSS 0.5%CVE-2026-47219HIGHfind-my-way is Vulnerable to DDoS with HTTP2EPSS 0.5%CVE-2026-30064HIGHImproper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of ServiEPSS 0.5%CVE-2026-42544HIGHGranian: Unauthenticated DoS via WebSocket subprotocol header panicEPSS 0.5%CVE-2026-67978HIGHAn issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN framEPSS 0.5%CVE-2026-30058HIGHImproper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a EPSS 0.5%CVE-2026-45291HIGHCloudburst Network erroneously handles invalid connectionsEPSS 0.5%CVE-2026-82003HIGHAdobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2026-30068HIGHImproper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial ofEPSS 0.5%CVE-2026-46679HIGHlibp2p: Memory DoS via subscription flood of unique topicsEPSS 0.5%CVE-2024-27613HIGHNumbas editor before 7.3 mishandles reading of themes and extensions.EPSS 0.5%CVE-2020-12521MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.EPSS 0.5%CVE-2023-21767HIGHWindows Overlay Filter Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-50553HIGHNote Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)EPSS 0.5%CVE-2023-21558HIGHWindows Error Reporting Service Elevation of Privilege VulnerabilityEPSS 0.5%