Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-5173MEDIUMHumanSignal label-studio-ml-backend PT File neural_nets.py load deserializationEPSS 0.2%CVE-2023-25951MEDIUMImproper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileEPSS 0.2%CVE-2025-69279HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2025-69278HIGHIn nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additionEPSS 0.2%CVE-2021-25509MEDIUMA missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the WiEPSS 0.2%CVE-2025-61084HIGHMDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. EPSS 0.2%CVE-2024-28977LOWDell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local attacker with low prEPSS 0.2%CVE-2026-6777MEDIUMOther issue in the Networking: DNS componentEPSS 0.2%CVE-2026-12025MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromisedEPSS 0.2%CVE-2024-10846MEDIUMExcessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loopEPSS 0.2%CVE-2026-42301HIGHImproper Input Validation leading to Improper Control of Generation of Code ('Code Injection') in pyp2specEPSS 0.2%CVE-2022-33945HIGHImproper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially EPSS 0.2%CVE-2026-14137MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who coEPSS 0.2%CVE-2022-36853LOWIntent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.EPSS 0.2%CVE-2026-18009MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spooEPSS 0.2%CVE-2026-100833HIGHContrast before 1.23.1 Image Substitution via Policy GenerationEPSS 0.2%CVE-2026-17939MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spooEPSS 0.2%CVE-2023-42012MEDIUMIBM UrbanCode Deploy denial of serviceEPSS 0.2%CVE-2023-21473MEDIUMImproper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitraryEPSS 0.2%CVE-2023-21472MEDIUMImproper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitraryEPSS 0.2%