Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2022-28126MEDIUMImproper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to poEPSS 0.2%CVE-2024-29074MEDIUMTelephony has an improper input validation vulnerabilityEPSS 0.2%CVE-2024-22382HIGHImproper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged usEPSS 0.2%CVE-2022-20507HIGHIn onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds cEPSS 0.2%CVE-2026-11034MEDIUMInsufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker toEPSS 0.2%CVE-2025-33043MEDIUMSMM buffer IntegrityEPSS 0.2%CVE-2024-28947HIGHImproper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow aEPSS 0.2%CVE-2024-13943HIGHTesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape VulnerabilityEPSS 0.2%CVE-2026-45328CRITICALESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service WrappersEPSS 0.2%CVE-2025-31488MEDIUMPlain Craft Launcher's custom homepage can use Internet Explorer to load web pages with the help of controls such as WebBrowserEPSS 0.2%CVE-2026-0416MEDIUMImproper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionalityEPSS 0.2%CVE-2022-42269HIGHNVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged lEPSS 0.2%CVE-2024-52880HIGHAn issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before versioEPSS 0.2%CVE-2026-12453MEDIUMInsufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2026-82738MEDIUMAsh.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of serviceEPSS 0.2%CVE-2026-65979MEDIUMOpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN)EPSS 0.2%CVE-2026-12034HIGHInsufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacEPSS 0.2%CVE-2026-82740LOWAsh.Type ignores outer array constraints on nested {:array, {:array, type}} inputsEPSS 0.2%CVE-2022-34443HIGH Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attaEPSS 0.2%CVE-2025-58114MEDIUMPotential XSS in Extension:CognitiveProcessDesignerEPSS 0.2%