Falhas do tipo CWE-20

5.450 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-1714HIGHAccess Request for Entitlement Values with Leading/Trailing WhitespaceEPSS 0.3%CVE-2024-1244CRITICALRemote code execution and local privilege escalation due to UNC access and NetNTLMv2 hash theftEPSS 0.3%CVE-2026-47181HIGHPenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account TakeoverEPSS 0.3%CVE-2025-47096LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2020-35509MEDIUMA flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticatoEPSS 0.3%CVE-2026-6779MEDIUMOther issue in the JavaScript Engine componentEPSS 0.3%CVE-2025-40846HIGHHaloITSM open redirect via the returnUrlEPSS 0.3%CVE-2026-65645MEDIUMRocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList anEPSS 0.3%CVE-2023-42431LOWPotential XSS on user preferences pageEPSS 0.3%CVE-2022-29192MEDIUMMissing validation crashes `QuantizeAndDequantizeV4Grad` in TensorFlowEPSS 0.3%CVE-2026-22615MEDIUMDue to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privilEPSS 0.3%CVE-2026-17795MEDIUMInappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendeEPSS 0.3%CVE-2026-63428MEDIUMHeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field setEPSS 0.3%CVE-2023-21596HIGHAdobe InCopy Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-25651MEDIUMSQL Injection Vulnerability in Some ZTE Mobile Internet ProductsEPSS 0.3%CVE-2025-12285CRITICALMissing Initial Password ChangeEPSS 0.3%CVE-2026-24811CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inffast.cEPSS 0.3%CVE-2026-100177MEDIUMAil Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Cookiejar AttachmentEPSS 0.3%CVE-2024-35384MEDIUMAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.EPSS 0.3%CVE-2022-29206MEDIUMMissing validation results in undefined behavior in `SparseTensorDenseAdd` in TensorFlowEPSS 0.3%