Falhas do tipo CWE-20

5.453 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2020-15709—add-apt-repository print ASNI terminal codesEPSS 0.3%CVE-2024-23705CRITICALIn multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could leadEPSS 0.3%CVE-2026-27170HIGHOpenSift: SSRF risk in URL ingestion endpointEPSS 0.3%CVE-2025-10433MEDIUM1Panel-dev MaxKB debug deserializationEPSS 0.3%CVE-2025-61614HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61613HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61615HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2026-5915HIGHInsufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bEPSS 0.3%CVE-2025-61612HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-61616HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2020-3201MEDIUMCisco IOS and IOS XE Software Tcl Denial of Service VulnerabilityEPSS 0.3%CVE-2023-0775MEDIUMBluetooth LE Invalid prepare write request command leads to denial of serviceEPSS 0.3%CVE-2024-41565MEDIUMJustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. TEPSS 0.3%CVE-2026-11460MEDIUMBoost Serialization improper validation of specified type of inputEPSS 0.3%CVE-2026-44337MEDIUMPraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queriesEPSS 0.3%CVE-2026-43725HIGHThe issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 andEPSS 0.3%CVE-2026-21683HIGHiccDEV has Type Confusion in icStatusCMM::CIccEvalCompare::EvaluateProfile()EPSS 0.3%CVE-2021-0168MEDIUMImproper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in WinEPSS 0.3%CVE-2025-44526MEDIUMRealtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low EPSS 0.3%CVE-2025-66866MEDIUMAn issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafEPSS 0.3%