Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-8518LOWCWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted proEPSS 0.2%CVE-2024-37027MEDIUMImproper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentiallEPSS 0.2%CVE-2026-32603HIGHSandboxie kernel driver denial of service via malformed IOCTL from sandboxed processEPSS 0.2%CVE-2023-4753LOWOpenHarmony v3.2.1 and prior version has a system call function usage errorEPSS 0.2%CVE-2023-24465MEDIUMCommunication Wi-Fi  subsystem has a null pointer reference vulnerability when receving external data.EPSS 0.2%CVE-2026-7961MEDIUMInsufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network sEPSS 0.2%CVE-2026-17870MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment EPSS 0.2%CVE-2026-17844MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment EPSS 0.2%CVE-2026-21768MEDIUMHCL Verse for Android is susceptible to an injection vulnerabilityEPSS 0.2%CVE-2026-21072MEDIUMImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2026-1858MEDIUMwget2 Improper Certificate ValidationEPSS 0.2%CVE-2026-21071MEDIUMImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memorEPSS 0.2%CVE-2026-21066MEDIUMImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2026-11286MEDIUMInsufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2024-55567HIGHImproper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62EPSS 0.2%CVE-2026-11126MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicEPSS 0.2%CVE-2025-11934LOWImproper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerifyEPSS 0.2%CVE-2021-37673MEDIUM`CHECK`-fail in `MapStage` in TensorFlowEPSS 0.2%CVE-2026-0412MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150 Web UIEPSS 0.2%CVE-2024-10083MEDIUMCWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver inEPSS 0.2%