Falhas do tipo CWE-20

5.453 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-0660MEDIUMStored XSS in Folder Function by Rogue AdminEPSS 0.3%CVE-2026-17679MEDIUMInsufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comproEPSS 0.3%CVE-2026-79288MEDIUMImproper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inEPSS 0.3%CVE-2025-24847MEDIUMImproper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an inEPSS 0.3%CVE-2026-13847MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leaEPSS 0.3%CVE-2025-8571MEDIUMConcrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard PageEPSS 0.3%CVE-2026-33588HIGHArbitrary File Write Through Path TraversalEPSS 0.3%CVE-2023-7248MEDIUMOpenText Vertica Management console might be prone to bypass via crafted requestsEPSS 0.3%CVE-2022-2868—libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacEPSS 0.3%CVE-2025-10061MEDIUMMalformed $group Query May Cause MongoDB Server to CrashEPSS 0.3%CVE-2024-0045HIGHIn smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proxiEPSS 0.3%CVE-2026-20715HIGHImproper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard ManageabEPSS 0.3%CVE-2026-18206LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching bypassEPSS 0.3%CVE-2026-87590MEDIUMImproper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive inforEPSS 0.3%CVE-2026-6231MEDIUMbson_validate may skip validation when processing certain inputsEPSS 0.3%CVE-2026-14225LOWEasy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist BypassEPSS 0.3%CVE-2022-29211MEDIUMSegfault in TensorFlow if `tf.histogram_fixed_width` is called with NaN valuesEPSS 0.3%CVE-2026-79013MEDIUMImproper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafEPSS 0.3%CVE-2023-22239HIGHAdobe After Effects Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-13889MEDIUMSide-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak crossEPSS 0.3%