Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-7962MEDIUMInsufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary readEPSS 0.2%CVE-2026-17906MEDIUMInsufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromiseEPSS 0.2%CVE-2025-46266MEDIUMUnauthenticated Transmission of Data in NomadBranch.exeEPSS 0.2%CVE-2026-17809MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisEPSS 0.2%CVE-2026-17908MEDIUMInsufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had EPSS 0.2%CVE-2026-19503MEDIUMInsufficient OIDC endpoint validation could invoke unintended local protocol handlersEPSS 0.2%CVE-2025-12278MEDIUMLogout Functionality not WorkingEPSS 0.2%CVE-2026-11031MEDIUMInsufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform EPSS 0.2%CVE-2026-11697CRITICALInsufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform aEPSS 0.2%CVE-2026-22748MEDIUMPotential Security Misconfiguration when Using withIssuerLocationEPSS 0.2%CVE-2024-0179HIGHSMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentiaEPSS 0.2%CVE-2026-7934MEDIUMInsufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had comproEPSS 0.2%CVE-2025-59596MEDIUMCVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14EPSS 0.2%CVE-2023-40394LOWThe issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be abEPSS 0.2%CVE-2026-46243HIGHsmb: client: reject userspace cifs.spnego descriptionsEPSS 0.2%CVE-2024-21925HIGHImproper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code exEPSS 0.2%CVE-2024-39827MEDIUMZoom Workplace Desktop App for Windows - Improper Input ValidationEPSS 0.2%CVE-2023-25776MEDIUMImproper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information dEPSS 0.2%CVE-2026-11246MEDIUMInsufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromiseEPSS 0.2%CVE-2023-42977HIGHA path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be abEPSS 0.2%