Falhas do tipo CWE-20

5.394 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-24446CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 1.8%CVE-2023-28731CRITICALUnauthenticated RCE affecting the AcyMailing plugin for JoomlaEPSS 1.8%CVE-2020-3141HIGHCisco IOS XE Software Privilege Escalation VulnerabilitiesEPSS 1.8%CVE-2018-20225HIGHAn issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intendedEPSS 1.8%CVE-2019-12663MEDIUMCisco IOS XE Software TrustSec Protected Access Credential Provisioning Denial of Service VulnerabilityEPSS 1.8%CVE-2020-15099HIGHExposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMSEPSS 1.8%CVE-2014-2345—COPA-DATA zenon DNP3 Improper Input ValidationEPSS 1.8%CVE-2019-1891HIGHCisco Small Business Series Switches HTTP Denial of Service VulnerabilityEPSS 1.8%CVE-2020-11261HIGHMemory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, EPSS 1.8%KEVCVE-2019-1817HIGHCisco Web Security Appliance Malformed Request Denial of Service VulnerabilityEPSS 1.8%CVE-2023-35365CRITICALWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.8%CVE-2019-1968MEDIUMCisco NX-OS Software NX-API Denial of Service VulnerabilityEPSS 1.8%CVE-2020-3309MEDIUMCisco Firepower Device Manager On-Box Software Arbitrary File Overwrite VulnerabilityEPSS 1.8%CVE-2020-36195CRITICALSQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-OnEPSS 1.8%CVE-2026-54402CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS tEPSS 1.8%CVE-2020-27125HIGHCisco Security Manager Static Credential VulnerabilityEPSS 1.8%CVE-2020-3471MEDIUMCisco Webex Meetings and Cisco Webex Meetings Server Unauthorized Audio Information Exposure VulnerabilityEPSS 1.8%CVE-2020-3302MEDIUMCisco Firepower Management Center File Overwrite VulnerabilityEPSS 1.7%CVE-2024-30054MEDIUMMicrosoft Power BI Client JavaScript SDK Information Disclosure VulnerabilityEPSS 1.7%CVE-2017-2617HIGHhawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a craEPSS 1.7%