Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2023-43570MEDIUM A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permEPSS 0.2%CVE-2024-5913MEDIUMPAN-OS: Improper Input Validation Vulnerability in PAN-OSEPSS 0.2%CVE-2026-9214MEDIUMInsufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.EPSS 0.2%CVE-2024-34545MEDIUMImproper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable infoEPSS 0.2%CVE-2022-35893HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxeEPSS 0.2%CVE-2026-11676HIGHInsufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker EPSS 0.2%CVE-2026-103237HIGHMISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant RowsEPSS 0.2%CVE-2019-1729MEDIUMCisco NX-OS Software Arbitrary File Overwrite VulnerabilityEPSS 0.2%CVE-2026-101041MEDIUMVulnerability-Lookup - Race Condition in Account Recovery Token Consumption Allows Password TakeoverEPSS 0.2%CVE-2026-21272HIGHDreamweaver Desktop | Improper Input Validation (CWE-20)EPSS 0.2%CVE-2022-31808HIGHA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V2.85.44), SiPass integrated ACC-AP (All versions <EPSS 0.2%CVE-2026-12016HIGHInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rendererEPSS 0.2%CVE-2026-11128MEDIUMInappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage iEPSS 0.2%CVE-2026-0415MEDIUMInsufficient input validation vulnerability in certain Orbi routersEPSS 0.2%CVE-2026-11093MEDIUMInappropriate implementation in Printing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2025-7375MEDIUMUnauthenticated Denial-of-Service Vulnerability in Omada EAP610EPSS 0.2%CVE-2026-11140MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process EPSS 0.2%CVE-2021-33142MEDIUMImproper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privilEPSS 0.2%CVE-2026-0417MEDIUMInsufficient input validation in certain NETGEAR routersEPSS 0.2%CVE-2022-1242HIGHApport can be tricked into connecting to arbitrary sockets as the root userEPSS 0.2%