Falhas do tipo CWE-20

5.439 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-95843HIGHMoquette malformed shared subscriptions can crash command processingEPSS 0.4%CVE-2023-22940MEDIUMSPL Command Safeguards Bypass via the ‘collect’ SPL Command Aliases in Splunk EnterpriseEPSS 0.4%CVE-2024-20274MEDIUMCisco Secure Firewall Management Center HTML Injection VulnerabilityEPSS 0.4%CVE-2026-84504HIGHfastify vulnerable to request body replacement via an async validation result collisionEPSS 0.4%CVE-2026-22072HIGHArbitrary URL Loading in WebView Leading to Token Leakage RiskEPSS 0.4%CVE-2026-53901HIGHCerebrate before v1.37 allows mass assignment of record identifiers during object creationEPSS 0.4%CVE-2025-59535MEDIUMDotNetNuke.Core allows loading of unused themes on anonymous clients through query parametersEPSS 0.4%CVE-2026-16551MEDIUMDenial-of-Service in OpenCanary's MongoDB moduleEPSS 0.4%CVE-2023-38417MEDIUMImproper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentiaEPSS 0.4%CVE-2016-2781MEDIUMchroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, whiEPSS 0.4%CVE-2026-6409HIGHDenial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted inputEPSS 0.4%CVE-2025-11936MEDIUMPotential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHelloEPSS 0.4%CVE-2024-7004MEDIUMInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.4%CVE-2026-31799MEDIUMTautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parametersEPSS 0.4%CVE-2026-32149HIGHWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-29143HIGHS/MIME Decryption ImpersonationEPSS 0.4%CVE-2023-0881HIGHDDoS in Ubuntu package linux-bluefieldEPSS 0.4%CVE-2026-22699HIGHRustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()EPSS 0.4%CVE-2017-12336—A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the intEPSS 0.4%CVE-2018-0302—A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attaEPSS 0.4%