Falhas do tipo CWE-20

5.453 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-34959MEDIUMAdminer before 5.5.0 Open Redirect via X-Forwarded-PrefixEPSS 0.3%CVE-2024-9407MEDIUMBuildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instructionEPSS 0.3%CVE-2026-16641CRITICALCommerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084EPSS 0.3%CVE-2024-45301MEDIUMZDI-CAN-24744: Mintty Path Conversion Improper Input Validation Information Disclosure VulnerabilityEPSS 0.3%CVE-2021-3599MEDIUMA potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local EPSS 0.3%CVE-2026-85528MEDIUMSnowflake JDBC Driver auto-configuration account validation permits credential redirectionEPSS 0.3%CVE-2024-25008MEDIUMEricsson RAN Compute and Site Controller 6610 - Improper Input Validation VulnerabilityEPSS 0.3%CVE-2026-59322MEDIUMEmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeadersEPSS 0.3%CVE-2026-0419MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150EPSS 0.3%CVE-2026-23840CRITICALMovary vulnerable to Cross-site Scripting with `?categoryDeleted=` paramEPSS 0.3%CVE-2025-24501MEDIUMAn improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.EPSS 0.3%CVE-2025-12842MEDIUMBooking Plugin for WordPress Appointments – Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email SendingEPSS 0.3%CVE-2026-14122HIGHInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker toEPSS 0.3%CVE-2026-3096MEDIUMReverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential TheftEPSS 0.3%CVE-2024-5439MEDIUMBlocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-15246MEDIUMaizuda snail-job API FurySerializer.deserialize deserializationEPSS 0.3%CVE-2021-38122MEDIUMCross-Site Scripting (XSS) in Advance AuthenticationEPSS 0.3%CVE-2026-92581MEDIUMAVideo through 29.0 Like Counter Desynchronization via Array ParameterEPSS 0.3%CVE-2026-33284LOWGlobalLeaks has insufficient URL validation in user support APIEPSS 0.3%CVE-2026-17791MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisedEPSS 0.3%