Falhas do tipo CWE-20

5.456 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-24484HIGHImproper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticEPSS 0.1%CVE-2026-81686MEDIUMopenssl_encrypt before 1.4.9 D-Bus Properties Authorization BypassEPSS 0.1%CVE-2025-24486HIGHImproper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticEPSS 0.1%CVE-2022-27829HIGHImproper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2025-7378MEDIUMAn improper input validation vulnerability was found on manipulating configuration of ADMEPSS 0.1%CVE-2022-27830HIGHImproper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2025-32004LOWImproper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalatiEPSS 0.1%CVE-2025-26474LOWcommunication_ipc an improper input validation vulnerabilityEPSS 0.1%CVE-2026-12456MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2025-20096MEDIUMImproper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adveEPSS 0.1%CVE-2022-39880HIGHImproper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary EPSS 0.1%CVE-2026-84666MEDIUMJenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration thEPSS 0.1%CVE-2026-12191HIGHComma AI Openpilot Pickle modeld.py pickle.loads deserializationEPSS 0.1%CVE-2025-24005HIGHLocal Privilege Escalation via Vulnerable SSH ScriptEPSS 0.1%CVE-2022-20457MEDIUMIn getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validatiEPSS 0.1%CVE-2022-20542HIGHIn parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation EPSS 0.1%CVE-2022-30754HIGHImplicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities witEPSS 0.1%CVE-2025-21086MEDIUMImproper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticEPSS 0.1%CVE-2022-30756HIGHImplicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with pEPSS 0.1%CVE-2023-28574CRITICALImproper Input Validation in CoreEPSS 0.1%