Falhas do tipo CWE-20

5.462 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-36929MEDIUMIn AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to loEPSS 0.1%CVE-2023-21092HIGHIn retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of SyEPSS 0.1%CVE-2024-20056MEDIUMIn preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilegeEPSS 0.1%CVE-2025-11195LOWRapid7 AppSpider Project Name Validation BypassEPSS 0.1%CVE-2026-102677HIGHElectron: Sandboxed preload code cache can be poisoned by a compromised rendererEPSS 0.1%CVE-2025-48559MEDIUMIn multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could EPSS 0.1%CVE-2025-48644MEDIUMIn multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial ofEPSS 0.1%CVE-2025-48556HIGHIn multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. ThEPSS 0.1%CVE-2025-48541HIGHIn onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. EPSS 0.1%CVE-2025-54636MEDIUMIssue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of thEPSS 0.1%CVE-2025-22424HIGHIn multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escaEPSS 0.1%CVE-2026-28578MEDIUMIn multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. ThisEPSS 0.1%CVE-2025-36920HIGHIn hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead tEPSS 0.1%CVE-2025-47314HIGHImproper Input Validation in Automotive Software platform based on QNXEPSS 0.1%CVE-2024-32903HIGHIn prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead EPSS 0.1%CVE-2025-48538MEDIUMIn setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to impropeEPSS 0.1%CVE-2025-27040MEDIUMImproper Input Validation in TZ FirmwareEPSS 0.1%CVE-2025-48643HIGHIn multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of priviEPSS 0.1%CVE-2026-11158HIGHInsufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentialEPSS 0.1%CVE-2024-56190HIGHIn wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to loEPSS 0.1%