Falhas do tipo CWE-20

5.456 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2021-25511MEDIUMAn improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path EPSS 0.1%CVE-2024-45577HIGHImproper Input Validation in Camera DriverEPSS 0.1%CVE-2021-25510MEDIUMAn improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.EPSS 0.1%CVE-2024-45579HIGHImproper Input Validation in Camera DriverEPSS 0.1%CVE-2024-51520MEDIUMVulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.1%CVE-2024-45444MEDIUMAccess permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confEPSS 0.1%CVE-2022-20019MEDIUMIn libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information discloEPSS 0.1%CVE-2025-31948MEDIUMImproper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applications may allow a deEPSS 0.1%CVE-2023-20634MEDIUMIn widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege withEPSS 0.1%CVE-2026-21088MEDIUMImproper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write EPSS 0.1%CVE-2024-51530MEDIUMLaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.1%CVE-2023-22382HIGHImproper Input Validation in AutomotiveEPSS 0.1%CVE-2024-31310HIGHIn newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill EPSS 0.1%CVE-2026-21086MEDIUMImproper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.EPSS 0.1%CVE-2026-101131MEDIUMdeepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decisionEPSS 0.1%CVE-2026-11241HIGHInsufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment EPSS 0.1%CVE-2026-58941HIGHIn multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local esEPSS 0.1%CVE-2021-25468MEDIUMA possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to readEPSS 0.1%CVE-2024-51514MEDIUMVulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect servEPSS 0.1%CVE-2024-51519MEDIUMVulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.1%