Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-25116MEDIUMSpecially crafted CF.RESERVE command can lead to denial-of-serviceEPSS 0.2%CVE-2025-5148MEDIUMFunAudioLLM InspireMusic Pickle Data model.py load_state_dict deserializationEPSS 0.2%CVE-2026-56732MEDIUMZammad: Malicious input in Ticket Body Enables Session TerminationEPSS 0.2%CVE-2025-43482MEDIUMThe issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. EPSS 0.2%CVE-2026-40317CRITICALNovumOS has Privilege Escalation in the Syscall InterfaceEPSS 0.2%CVE-2026-91819MEDIUMMISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponentEPSS 0.2%CVE-2025-4742MEDIUMXU-YIJIE grpo-flat grpo_vanilla.py main deserializationEPSS 0.2%CVE-2025-4701MEDIUMVITA-MLLM Freeze-Omni utils.py torch.load deserializationEPSS 0.2%CVE-2022-45469LOWImproper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via lEPSS 0.2%CVE-2026-25684MEDIUMFile Type Control rule bypassEPSS 0.2%CVE-2025-4740MEDIUMBeamCtrl Airiana coef deserializationEPSS 0.2%CVE-2024-0080LOW NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specEPSS 0.2%CVE-2024-22390MEDIUMImproper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.EPSS 0.2%CVE-2026-84947LOWundici vulnerable to response truncation via oversized chunked responses in the dump interceptorEPSS 0.2%CVE-2022-32577LOWImproper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enablEPSS 0.2%CVE-2026-24347MEDIUMArbitrary file write to /tmp directory in EZCast Pro II DongleEPSS 0.2%CVE-2023-22662MEDIUMImproper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user tEPSS 0.2%CVE-2026-45055HIGHCubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host HeaderEPSS 0.2%CVE-2026-9982HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2022-23403MEDIUMImproper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enaEPSS 0.2%