Falhas do tipo CWE-20

5.454 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2021-34755MEDIUMCisco Firepower Threat Defense Software Command Injection VulnerabilitiesEPSS 0.3%CVE-2026-17909MEDIUMInsufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crEPSS 0.3%CVE-2023-5058—Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentialEPSS 0.3%CVE-2019-15273MEDIUMCisco TelePresence Collaboration Endpoint Software Arbitrary File Overwrite VulnerabilitiesEPSS 0.3%CVE-2026-34773MEDIUMElectron: Registry key path injection in app.setAsDefaultProtocolClient on WindowsEPSS 0.3%CVE-2022-28193MEDIUMNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted daEPSS 0.3%CVE-2026-17698HIGHInsufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-oEPSS 0.3%CVE-2022-28186MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the EPSS 0.3%CVE-2026-71390MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2026-70589MEDIUMGhost: Archived Offers can be RedeemedEPSS 0.3%CVE-2022-28188MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the EPSS 0.3%CVE-2026-33797HIGHJunos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP resetEPSS 0.3%CVE-2022-21933MEDIUMASUS VivoMini/Mini PC - improper input validationEPSS 0.3%CVE-2025-61652LOWAction API discussiontoolspageinfo does not check for authorizeRead for the pageEPSS 0.3%CVE-2026-23880HIGHOnboardLite has stored Cross-site Scripting issue that may lead to admin Account Take OverEPSS 0.3%CVE-2026-11738MEDIUMInsufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.EPSS 0.3%CVE-2022-1107MEDIUMDuring an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovereEPSS 0.3%CVE-2020-12487HIGHCommand Execution Vulnerability in ABE serviceEPSS 0.3%CVE-2026-51598MEDIUMAn input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticateEPSS 0.3%CVE-2024-21974HIGHImproper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary cEPSS 0.3%