Falhas do tipo CWE-20

5.393 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2019-18228—Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HEPSS 2.1%CVE-2021-1275CRITICALCisco SD-WAN vManage Software VulnerabilitiesEPSS 2.1%CVE-2018-15369—Cisco IOS and IOS XE Software TACACS+ Client Denial of Service VulnerabilityEPSS 2.1%CVE-2023-28707HIGHAirflow Apache Drill Provider Arbitrary File Read VulnerabilityEPSS 2.1%CVE-2025-34118HIGHLinknat VOS Manager Path Traversal File DisclosureEPSS 2.1%CVE-2022-42837CRITICALAn issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOSEPSS 2.1%CVE-2020-7069MEDIUMWrong ciphertext/tag in AES-CCM encryption for a 12 bytes IVEPSS 2.1%CVE-2024-6436HIGHRockwell Automation Input Validation Vulnerability exists in the SequenceManager™ ServerEPSS 2.1%CVE-2021-37533MEDIUMApache Commons Net's FTP client trusts the host from PASV response by defaultEPSS 2.1%CVE-2020-28221—A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the EPSS 2.1%CVE-2019-1806HIGHCisco Small Business Series Switches Simple Network Management Protocol Denial of Service VulnerabilityEPSS 2.0%CVE-2023-32015CRITICALWindows Pragmatic General Multicast (PGM) Remote Code Execution VulnerabilityEPSS 2.0%CVE-2022-31778—Transfer-Encoding not treated as hop-by-hopEPSS 2.0%CVE-2026-2113MEDIUMyuan1994 tpadmin WebUploader preview.php deserializationEPSS 2.0%CVE-2019-1721HIGHCisco Expressway Series and Cisco TelePresence Video Communication Server Denial of Service VulnerabilityEPSS 2.0%CVE-2019-1697MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Lightweight Directory Access Protocol Denial of Service VulnerabilityEPSS 2.0%CVE-2014-0761—CG Automation ePAQ-9410 Substation Gateway Improper Input ValidationEPSS 2.0%CVE-2018-7511—In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in EPSS 2.0%CVE-2021-1468CRITICALCisco SD-WAN vManage Software VulnerabilitiesEPSS 2.0%CVE-2023-36821HIGHUptime Kuma vulnerable to authenticated remote code execution via malicious plugin installationEPSS 2.0%