Falhas do tipo CWE-20

5.456 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2022-33216MEDIUMImproper Input Validation in AutomotiveEPSS 0.1%CVE-2024-51514MEDIUMVulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect servEPSS 0.1%CVE-2025-62816MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP iEPSS 0.1%CVE-2025-48612HIGHIn setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment settiEPSS 0.1%CVE-2025-52347HIGHAn issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 BuEPSS 0.1%CVE-2024-45446MEDIUMAccess permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect aEPSS 0.1%CVE-2026-61079MEDIUMVulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 2EPSS 0.1%CVE-2022-20392HIGHIn declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent dEPSS 0.1%CVE-2026-101079LOWagentverus agentverus-scanner context.js isSecurityDefenseSkill reliance on untrusted inputs in a security decisionEPSS 0.1%CVE-2024-51529MEDIUMData verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.EPSS 0.1%CVE-2022-36850MEDIUMPath traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.EPSS 0.1%CVE-2022-27833MEDIUMImproper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.EPSS 0.1%CVE-2024-49844HIGHImproper Input Validation in AutomotiveEPSS 0.1%CVE-2024-49845HIGHImproper Input Validation in HLOSEPSS 0.1%CVE-2023-20932LOWIn onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input valEPSS 0.1%CVE-2021-25512MEDIUMAn improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2025-21460HIGHImproper Input Validation in Automotive Software platform based on QNXEPSS 0.1%CVE-2021-25453MEDIUMSome improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.EPSS 0.1%CVE-2025-48623HIGHIn init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalatiEPSS 0.1%CVE-2022-33704HIGHImproper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activitiEPSS 0.1%