Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-25743HIGHIn the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGEPSS 0.2%CVE-2022-28196MEDIUMNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusteEPSS 0.2%CVE-2022-33894HIGHImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of EPSS 0.2%CVE-2026-21268HIGHDreamweaver Desktop | Improper Input Validation (CWE-20)EPSS 0.2%CVE-2021-26323—Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.EPSS 0.2%CVE-2022-28195MEDIUMNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrustedEPSS 0.2%CVE-2026-60620MEDIUMVulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supportEPSS 0.2%CVE-2025-64747MEDIUMDirectus Vulnerable to Stored Cross-site ScriptingEPSS 0.2%CVE-2026-12009HIGHInsufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who haEPSS 0.2%CVE-2026-79000MEDIUMImproper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging sociEPSS 0.2%CVE-2026-79272LOWImproper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer pEPSS 0.2%CVE-2021-25441—Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applicatiEPSS 0.2%CVE-2026-7965LOWInsufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromisedEPSS 0.2%CVE-2025-12741HIGHArbitrary File Write in Denodo dialect of Looker allows Remote Code ExecutionEPSS 0.2%CVE-2026-17955MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofEPSS 0.2%CVE-2026-14089MEDIUMInsufficient validation of untrusted input in PopupBlocker in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromEPSS 0.2%CVE-2026-13995MEDIUMInsufficient validation of untrusted input in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perfoEPSS 0.2%CVE-2026-0406MEDIUMInsufficient input validation in NETGEAR Nighthawk router XR1000v2EPSS 0.2%CVE-2024-28976HIGHDell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privilegeEPSS 0.2%CVE-2026-14140MEDIUMInsufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform EPSS 0.2%