Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-36282HIGHImproper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged EPSS 0.2%CVE-2022-43875MEDIUMIBM Financial Transaction Manager for SWIFT Services for Multiplatforms denial of serviceEPSS 0.2%CVE-2023-34086HIGHImproper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via lEPSS 0.2%CVE-2023-44110—Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2026-15088MEDIUMDevelopment Environment - Critical - Unsupported - SA-CONTRIB-2026-089EPSS 0.2%CVE-2024-21871HIGHImproper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privEPSS 0.2%CVE-2026-17970MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network EPSS 0.2%CVE-2026-43989HIGHJunoClaw: upload_wasm accepted arbitrary filesystem paths without validationEPSS 0.2%CVE-2022-42477MEDIUMAn improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may EPSS 0.2%CVE-2026-13999MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user toEPSS 0.2%CVE-2026-73768HIGHLocal Privilege Escalation in AOS-CX Command Line InterfaceEPSS 0.2%CVE-2026-11251LOWInsufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2026-11240LOWInsufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2026-87071MEDIUMForminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted PostsEPSS 0.2%CVE-2024-0127HIGHNVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of thEPSS 0.2%CVE-2023-21439HIGHImproper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activitieEPSS 0.2%CVE-2021-37665HIGHIncomplete validation in MKL requantization in TensorFlowEPSS 0.2%CVE-2026-16422HIGHInsufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileEPSS 0.2%CVE-2025-43472HIGHA validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS TEPSS 0.2%CVE-2022-38787MEDIUMImproper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentiEPSS 0.2%