Falhas do tipo CWE-20

5.450 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-43375HIGHThe issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.EPSS 0.3%CVE-2025-59940MEDIUMmkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholdersEPSS 0.3%CVE-2026-100177MEDIUMAil Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Cookiejar AttachmentEPSS 0.3%CVE-2024-35384MEDIUMAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.EPSS 0.3%CVE-2024-2536MEDIUMRank Math SEO with AI SEO Tools <= 1.0.214 - Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributesEPSS 0.3%CVE-2025-56404HIGHAn issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks uEPSS 0.3%CVE-2021-1432HIGHCisco IOS XE SD-WAN Software Arbitrary Command Execution VulnerabilityEPSS 0.3%CVE-2026-2695MEDIUMLack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)EPSS 0.3%CVE-2024-6541MEDIUMInformation Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 ProductsEPSS 0.3%CVE-2014-2346—COPA-DATA zenon DNP3 Improper Input ValidationEPSS 0.3%CVE-2020-16237LOWPhilips SureSigns VS4 Improper Input ValidationEPSS 0.3%CVE-2026-91738CRITICALImproper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code oEPSS 0.3%CVE-2023-38654HIGHImproper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticatedEPSS 0.3%CVE-2026-46341MEDIUMApify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix MatchingEPSS 0.3%CVE-2024-0126HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A EPSS 0.3%CVE-2022-4332MEDIUMSprecher: Vulnerable firmware verificationEPSS 0.3%CVE-2022-46701HIGHThe issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. ConnectEPSS 0.3%CVE-2026-94091MEDIUMpiskvorky gensim Model Loader utils.py load deserializationEPSS 0.3%CVE-2026-59650CRITICALMTI/A0 DH agreement exponentiates unvalidated peer valueEPSS 0.3%CVE-2020-3435MEDIUMCisco AnyConnect Secure Mobility Client for Windows Profile Modification VulnerabilityEPSS 0.3%