Falhas do tipo CWE-20

5.451 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-55630LOWDOM Clobbering leads to temporary DOS in the note viewer in JoplinEPSS 0.3%CVE-2026-69295HIGHWindows USB Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-32168HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-76330HIGHSPL Injection through Monitoring Console Forwarder Filters in Splunk EnterpriseEPSS 0.3%CVE-2026-73021HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70581HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-49234HIGHRoutinator crashes on specifically crafted ASN strings in the APIEPSS 0.3%CVE-2026-26161HIGHWindows Sensor Data Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69270HIGHWindows USB Audio Class driver (usbaudio.sys) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-0658HIGHAutomated Logic and Carrier Zone Controllers malformed packets denial of serviceEPSS 0.3%CVE-2026-72996HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-44811HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26170HIGHPowerShell Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-76332HIGHSPL Injection through Splunk Web in Splunk EnterpriseEPSS 0.3%CVE-2026-54299HIGHAstro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)EPSS 0.3%CVE-2026-69293HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69352HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-72994HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-39410MEDIUMHono has a non-breaking space prefix bypass in cookie name handling in getCookie()EPSS 0.3%CVE-2023-25865HIGHAdobe Substance 3D Stager OBJ File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%