Falhas do tipo CWE-20

5.441 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-3967MEDIUMAlfresco Activiti Process Variable Serialization System SerializableType.java createObjectInputStream deserializationEPSS 0.4%CVE-2026-27906MEDIUMWindows Hello Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2022-23425HIGHImproper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with EPSS 0.4%CVE-2026-90490MEDIUMlenve vhr MailReceiver deserializationEPSS 0.4%CVE-2026-55072HIGHPimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table nameEPSS 0.4%CVE-2026-8735MEDIUMOinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserializationEPSS 0.4%CVE-2026-3470LOWA vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowiEPSS 0.4%CVE-2023-24062MEDIUMDiebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory strucEPSS 0.4%CVE-2026-9497MEDIUMchangmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserializationEPSS 0.4%CVE-2026-7712MEDIUMMindsDB Pickle pickle.loads deserializationEPSS 0.4%CVE-2026-83492MEDIUMWordPress Kubio AI Website Builder - Denial Of ServiceEPSS 0.4%CVE-2026-12787MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserializationEPSS 0.4%CVE-2025-1741MEDIUMb1gMail Admin Page users.php deserializationEPSS 0.4%CVE-2024-48918HIGHLack of Input Validation in RDS Light - Potential for Injection Attacks and Memory TamperingEPSS 0.4%CVE-2026-27585MEDIUMCaddy's improper sanitization of glob characters in file matcher may lead to bypassing security protectionsEPSS 0.4%CVE-2023-2808MEDIUMLack of URL normalization allows rendering previews for disallowed domainsEPSS 0.4%CVE-2026-20254MEDIUMInformation Disclosure through External Content Restriction Bypass in Splunk EnterpriseEPSS 0.4%CVE-2023-0869MEDIUMCross-site scripting in outage/list.htmEPSS 0.4%CVE-2023-42508MEDIUMJFrog Artifactory Improper header input validation leads to email manipulation sent from the platformEPSS 0.4%CVE-2024-25999HIGHPHOENIX CONTACT: Privilege escalation in the OCPP agent serviceEPSS 0.4%