Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2023-42766HIGHImproper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of EPSS 0.2%CVE-2025-24308HIGHImproper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentEPSS 0.2%CVE-2025-20034MEDIUMImproper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards before vEPSS 0.2%CVE-2025-20009MEDIUMImproper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards may allow a privilegeEPSS 0.2%CVE-2023-38587HIGHImproper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via locaEPSS 0.2%CVE-2023-29495HIGHImproper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2025-11143LOWThe Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs EPSS 0.2%CVE-2023-28743HIGHImproper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2022-27826HIGHImproper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.2%CVE-2026-86924MEDIUMA memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 2EPSS 0.2%CVE-2024-33659MEDIUMBiosGuard Buffer Overflow and TOCTOU VulnerabilityEPSS 0.2%CVE-2026-54577LOWmport audit can inspect the wrong package when options are presentEPSS 0.2%CVE-2026-5941HIGHFoxit PDF Editor/Reader AcroForm Signature Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-47470MEDIUMNVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by EPSS 0.2%CVE-2023-31339MEDIUMImproper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform EPSS 0.2%CVE-2024-8518LOWCWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted proEPSS 0.2%CVE-2026-50144HIGHncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negative parameter idEPSS 0.2%CVE-2026-23566MEDIUMLog Injection in Content Distribution Service UDP HandlerEPSS 0.2%CVE-2026-24345MEDIUMCross-Site Request Forgery in EZCast Pro II DongleEPSS 0.2%CVE-2026-11273MEDIUMInsufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a userEPSS 0.2%