Falhas do tipo CWE-20

5.456 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-48623HIGHIn init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalatiEPSS 0.1%CVE-2024-0022MEDIUMIn multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another usEPSS 0.1%CVE-2024-23706HIGHIn multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local eEPSS 0.1%CVE-2026-77797LOWVelociraptor Prefetch parser out of boundsEPSS 0.1%CVE-2026-27765MEDIUMImproper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User ApplicationEPSS 0.1%CVE-2026-21089MEDIUMImproper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-ofEPSS 0.1%CVE-2026-17503MEDIUMThis Power System update is being released to addressEPSS 0.1%CVE-2025-68964MEDIUMData verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-20913MEDIUMImproper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escEPSS 0.1%CVE-2025-29936HIGHImproper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentiEPSS 0.1%CVE-2026-7990HIGHInsufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to performEPSS 0.1%CVE-2024-58044HIGHPermission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect avaEPSS 0.1%CVE-2026-13849HIGHInsufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to poteEPSS 0.1%CVE-2026-7997HIGHInsufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local attacker to perform OS-EPSS 0.1%CVE-2025-14963MEDIUMA vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevatedEPSS 0.1%CVE-2024-38420HIGHImproper Input Validation in HypervisorEPSS 0.1%CVE-2024-43052HIGHImproper Input Validation in Video Analytics and ProcessingEPSS 0.1%CVE-2026-34855MEDIUMOut-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and cEPSS 0.1%CVE-2024-38413MEDIUMImproper Input Validation in Computer VisionEPSS 0.1%CVE-2021-25500HIGHA missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.EPSS 0.1%