Falhas do tipo CWE-20

5.455 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-21065MEDIUMOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2024-41167HIGHImproper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to potentially enable EPSS 0.2%CVE-2024-22338MEDIUMIBM Security Verify Access OIDC Provider information disclosureEPSS 0.2%CVE-2024-39811MEDIUMImproper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalatiEPSS 0.2%CVE-2026-43722MEDIUMThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.EPSS 0.2%CVE-2026-35369MEDIUMuutils coreutils kill System-wide Process Termination and Denial of Service via Argument MisinterpretationEPSS 0.2%CVE-2026-78237HIGHInsufficient input validation in Admin By Request (ABR)EPSS 0.2%CVE-2024-38483MEDIUMDell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local acEPSS 0.2%CVE-2026-34383MEDIUMAdmidio: CSRF and Form Validation Bypass in Inventory Item Save via `imported` ParameterEPSS 0.2%CVE-2026-43895MEDIUMjq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifactsEPSS 0.2%CVE-2026-20627MEDIUMAn issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.EPSS 0.2%CVE-2023-31366LOWImproper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of EPSS 0.1%CVE-2017-3772MEDIUMA vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.EPSS 0.1%CVE-2026-56975MEDIUMIn Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denEPSS 0.1%CVE-2025-24296MEDIUMImproper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial ofEPSS 0.1%CVE-2026-60526MEDIUMVulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. EPSS 0.1%CVE-2026-30769HIGHAn issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sEPSS 0.1%CVE-2026-11221MEDIUMInsufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromiEPSS 0.1%CVE-2026-35347MEDIUMuutils coreutils comm Silent Data Loss or Denial of Service via Improper Input ValidationEPSS 0.1%CVE-2021-37677MEDIUMMissing validation in shape inference for `Dequantize` in TensorFlowEPSS 0.1%