Falhas do tipo CWE-20

5.456 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-6969MEDIUMability_ability_runtime an improper input validation vulnerabilityEPSS 0.1%CVE-2021-37677MEDIUMMissing validation in shape inference for `Dequantize` in TensorFlowEPSS 0.1%CVE-2026-62425MEDIUMbuffer overruns in libfsimage iso9660 handlingEPSS 0.1%CVE-2026-35347MEDIUMuutils coreutils comm Silent Data Loss or Denial of Service via Improper Input ValidationEPSS 0.1%CVE-2024-0158MEDIUMDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exEPSS 0.1%CVE-2025-52651LOWHCL MyXalytics is affected by multiple security vulnerabilities.EPSS 0.1%CVE-2026-11205MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who coEPSS 0.1%CVE-2026-45317MEDIUMOpen WebUI: Cross-Site Request Forgery (CSRF) via Image URL ManipulationEPSS 0.1%CVE-2026-30901HIGHZoom Rooms for Windows - Improper Input ValidationEPSS 0.1%CVE-2022-20512HIGHIn navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation.EPSS 0.1%CVE-2024-42424MEDIUMDell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attackeEPSS 0.1%CVE-2026-4407LOWOut-of-bounds array write in Xpdf 4.06 due to missing validationEPSS 0.1%CVE-2024-20394MEDIUMA vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DEPSS 0.1%CVE-2025-69205MEDIUMIn µURU, a Specially Crafted Federation Name Allows Dialplan InjectionEPSS 0.1%CVE-2024-38303MEDIUMDell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged aEPSS 0.1%CVE-2025-24325CRITICALImproper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticEPSS 0.1%CVE-2024-43697LOWLiteos_a has an Improper Input Validation vulnerabilityEPSS 0.1%CVE-2022-28781HIGHImproper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. TEPSS 0.1%CVE-2026-39020MEDIUMAn issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ fileEPSS 0.1%CVE-2026-47542MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper inpEPSS 0.1%