Falhas do tipo CWE-20

5.442 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-29150MEDIUMBlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.EPSS 0.4%CVE-2019-1726MEDIUMCisco NX-OS Software CLI Bypass to Internal Service VulnerabilityEPSS 0.4%CVE-2026-21061MEDIUMImproper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User inEPSS 0.4%CVE-2026-27818HIGHTerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlistEPSS 0.4%CVE-2026-52877HIGHStreambert : Insecure Protocol Execution in open-external IPC HandlerEPSS 0.4%CVE-2021-29913MEDIUMIBM Security Verify Privilege improper input validationEPSS 0.4%CVE-2025-59161LOWIn Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is leftEPSS 0.4%CVE-2026-48569HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2023-32820HIGHIn wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with noEPSS 0.4%CVE-2026-27607HIGHRustFS's Missing Post Policy Validation leads to Arbitrary Object WriteEPSS 0.4%CVE-2024-1471MEDIUMHTML Injection VulnerabilityEPSS 0.4%CVE-2025-3590MEDIUMAdianti Framework deserializationEPSS 0.4%CVE-2026-13603CRITICALSSRF with API key leak in pretix-oppwaEPSS 0.4%CVE-2026-95674MEDIUMMISP EventsController queryEnrichment allows querying unavailable or legacy modules without validationEPSS 0.4%CVE-2026-47662HIGHPathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLsEPSS 0.4%CVE-2025-59895HIGHRemote denial-of-service (DoS) vulnerability in Sync Breeze Enterprise ServerEPSS 0.4%CVE-2023-0896HIGHA default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attackEPSS 0.4%CVE-2023-2267MEDIUMImproper input validation could lead to reflection injection attacksEPSS 0.4%CVE-2021-1367MEDIUMCisco NX-OS Software Protocol Independent Multicast Denial of Service VulnerabilityEPSS 0.4%CVE-2025-50490HIGHImproper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attacEPSS 0.4%