Falhas do tipo CWE-20

5.450 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-5455HIGHPossible denial of service when passing malformed data in a URL to qDecodeDataUrlEPSS 0.4%CVE-2026-3912HIGHTIBCO ActiveMatrix BusinessWorks Injection VulnerabilityEPSS 0.4%CVE-2026-4982HIGHUnauthorized access to chat contentsEPSS 0.4%CVE-2023-38057MEDIUMXSS stored in survey answersEPSS 0.4%CVE-2023-4553MEDIUMUnauthenticated Access to AppBuilder Configuration FilesEPSS 0.4%CVE-2025-54785HIGHSuiteCRM is Vulnerable to PHP Object Injection in ReportsEPSS 0.4%CVE-2025-2305HIGHLocal file inclusion vulnerability in LIVE CONTRACTEPSS 0.4%CVE-2026-30576HIGHA Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application faEPSS 0.4%CVE-2024-37406HIGHIn Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domEPSS 0.4%CVE-2026-13602HIGHSession takeover vulnerabilityEPSS 0.4%CVE-2026-54728MEDIUMbunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWebEPSS 0.4%CVE-2015-6563MEDIUMThe monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX reEPSS 0.4%CVE-2026-33369MEDIUMZimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operatioEPSS 0.4%CVE-2026-25126HIGHPolarLearn's unvalidated vote direction allows vote count manipulationEPSS 0.4%CVE-2023-3434MEDIUMQRC Handler without Input Validation in JamiEPSS 0.4%CVE-2025-3622MEDIUMXorbits Inference model.py load deserializationEPSS 0.4%CVE-2026-53541MEDIUMOliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input FilteringEPSS 0.4%CVE-2024-20334MEDIUMA vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attaEPSS 0.4%CVE-2026-67969HIGHAn issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a craftEPSS 0.4%CVE-2026-46669HIGH`openvm-pairing` pairing check missing proper subfield check on scaling factorEPSS 0.4%