Falhas do tipo CWE-20

5.443 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-41849MEDIUMAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.4%CVE-2025-6585HIGHWP JobHunt <= 7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Account DeletionEPSS 0.4%CVE-2026-85170HIGHn8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodesEPSS 0.4%CVE-2022-46328HIGHSome smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.EPSS 0.4%CVE-2025-32076MEDIUMEvil regex used to process user-provided data in VisualDataEPSS 0.4%CVE-2025-32075MEDIUMIP and user agent leaks in Extension:TabsEPSS 0.4%CVE-2023-36466LOWTopic Title Validation Skipped When Changing Category in DiscourseEPSS 0.4%CVE-2021-25471LOWA lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile EPSS 0.4%CVE-2024-7512MEDIUMConcrete CMS Stored XSS in Board instancesEPSS 0.4%CVE-2017-15121—A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that dEPSS 0.4%CVE-2024-31227MEDIUMDenial-of-service due to malformed ACL selectors in RedisEPSS 0.4%CVE-2022-45871MEDIUMDenial-of-Service (DoS) VulnerabilityEPSS 0.4%CVE-2026-47196HIGHQuest Bot: Empty automod rule causes every guild message to be deletedEPSS 0.4%CVE-2026-45393HIGHLocal privilege escalation to SYSTEM in Cribl Edge for WindowsEPSS 0.4%CVE-2025-52894MEDIUMOpenBao Vulnerable to Unauthenticated Rekey Operation CancellationEPSS 0.4%CVE-2026-29133MEDIUMUID Regex BypassEPSS 0.4%CVE-2020-10058HIGHMultiple Syscalls In kscan Subsystem Performs No Argument ValidationEPSS 0.4%CVE-2023-4435HIGHImproper Input Validation in hamza417/inureEPSS 0.4%CVE-2026-73158MEDIUMcti-transmute Saved Graph Configuration Allows Stored Cross-Site Scripting via svgIconEPSS 0.4%CVE-2020-10028HIGHMultiple Syscalls In GPIO Subsystem Performs No Argument ValidationEPSS 0.4%