Falhas do tipo CWE-20

5.394 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2025-34132CRITICALLILIN DVR Command Injection via NTPUpdate in dvr_boxEPSS 1.7%CVE-2019-15288HIGHCisco TelePresence Collaboration Endpoint, TelePresence Codec, and RoomOS Software Privilege Escalation VulnerabilityEPSS 1.7%CVE-2018-12479MEDIUMRequest controller allows to create requests with arbitrary request IDsEPSS 1.7%CVE-2020-3170MEDIUMCisco NX-OS Software NX-API Denial of Service VulnerabilityEPSS 1.7%CVE-2018-15449MEDIUMCisco Video Surveillance Media Server Denial of Service VulnerabilityEPSS 1.7%CVE-2024-3646HIGHCommand injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management ConsoleEPSS 1.7%CVE-2018-0117—A vulnerability in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software cEPSS 1.7%CVE-2020-3496MEDIUMCisco Small Business Smart and Managed Switches Denial of Service VulnerabilityEPSS 1.7%CVE-2023-21816HIGHWindows Active Directory Domain Services API Denial of Service VulnerabilityEPSS 1.7%CVE-2017-12215—A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unautEPSS 1.7%CVE-2018-6589—CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecifEPSS 1.7%CVE-2022-35724—Denial of service while reading data in Avro Rust SDKEPSS 1.7%CVE-2017-9022HIGHThe gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers EPSS 1.7%CVE-2023-36407HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 1.7%CVE-2024-31865MEDIUMApache Zeppelin: Cron arbitrary user impersonation with improper privilegesEPSS 1.7%CVE-2024-1354HIGHCommand injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement ConsoleEPSS 1.7%CVE-2021-32795MEDIUMDenial of Service via Steam chat in ArchiSteamFarmEPSS 1.7%CVE-2019-6555—Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may EPSS 1.7%CVE-2022-28711MEDIUMA memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac - master branch 46177EPSS 1.7%CVE-2021-40712MEDIUMAdobe Experience Manager Path parameter Improper Input Validation Could Lead To DOSEPSS 1.7%