Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-44779MEDIUMAn issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.EPSS 0.2%CVE-2026-13006HIGHIncomplete protection against CVE-2025-11226EPSS 0.2%CVE-2022-37327MEDIUMImproper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 EPSS 0.2%CVE-2024-3173HIGHInsufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escaEPSS 0.2%CVE-2025-27493CRITICALA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < VEPSS 0.2%CVE-2023-24571HIGH Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with administrator privileges could potEPSS 0.2%CVE-2025-66225HIGHOrangeHRM is Vulnerable to Account Takeover Through Unvalidated Username in Password Reset WorkflowEPSS 0.2%CVE-2024-36482HIGHImproper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2022-32490HIGH Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabilEPSS 0.2%CVE-2024-27240HIGHZoom Apps for Windows - Improper Input ValidationEPSS 0.2%CVE-2022-32144HIGHThere is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to serviEPSS 0.2%CVE-2023-25522HIGH NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by providing configuratiEPSS 0.2%CVE-2023-32633MEDIUMImproper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially eEPSS 0.2%CVE-2026-60640HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-76816LOWNetty: MQTT Topic Name and Client ID Validation BypassEPSS 0.2%CVE-2026-10942HIGHInappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform privilege escalatiEPSS 0.2%CVE-2022-20590MEDIUMIn valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lEPSS 0.2%CVE-2023-25772MEDIUMImproper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may allow an authenticateEPSS 0.2%CVE-2022-20592MEDIUMIn ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local iEPSS 0.2%CVE-2026-28852MEDIUMA stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4EPSS 0.2%