Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-55371MEDIUMOpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_lengthEPSS 0.2%CVE-2026-53409HIGHImproper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of priEPSS 0.2%CVE-2026-62293MEDIUMHAPI FHIR: Stored XSS in scan report via unescaped IG and profile titlesEPSS 0.2%CVE-2026-22568MEDIUMUnauthorized information retrieval in ZIA Admin UIEPSS 0.2%CVE-2026-45329HIGHESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service WrappersEPSS 0.2%CVE-2023-39251MEDIUM Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vEPSS 0.2%CVE-2023-31028LOW NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a EPSS 0.2%CVE-2025-4424MEDIUMSetupAutomationSmm : Arbitrary calls to SmmSetVariable with unsanitised arguments in SMI handlerEPSS 0.2%CVE-2024-34163HIGHImproper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via locEPSS 0.2%CVE-2021-22280HIGHDLL Hijacking Vulnerability in Automation StudioEPSS 0.2%CVE-2026-45676MEDIUMOpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agentEPSS 0.2%CVE-2026-24348HIGHMultiple cross-site scripting vulnerabilities in EZCast Pro II DongleEPSS 0.2%CVE-2026-43724HIGHThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.EPSS 0.2%CVE-2025-71011MEDIUMAn input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allowsEPSS 0.2%CVE-2025-71009MEDIUMAn input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of SerEPSS 0.2%CVE-2026-1225LOWMalicious logback.xml configuration file allows instantiation of arbitrary classesEPSS 0.2%CVE-2026-11686LOWInsufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had comprEPSS 0.2%CVE-2021-25450MEDIUMPath traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remEPSS 0.2%CVE-2024-21781HIGHImproper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or deniEPSS 0.2%CVE-2025-13462LOWtarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handlingEPSS 0.2%