Falhas do tipo CWE-20

5.399 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2018-15424—Multiple Vulnerabilities in Cisco Identity Services EngineEPSS 1.4%CVE-2021-1260HIGHCisco SD-WAN Command Injection VulnerabilitiesEPSS 1.4%CVE-2021-1261HIGHCisco SD-WAN Command Injection VulnerabilitiesEPSS 1.4%CVE-2022-1053—Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and tEPSS 1.4%CVE-2026-59509CRITICALUnauthenticated arbitrary MongoDB collection read in cve-searchEPSS 1.4%CVE-2026-21893CRITICALn8n Vulnerable to Command Injection in Community Package InstallationEPSS 1.4%CVE-2020-15181CRITICALAdmin account takeover in Alfresco Reset PasswordEPSS 1.4%CVE-2026-48281CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 1.4%CVE-2017-12276—A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allEPSS 1.4%CVE-2024-38265HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-20758CRITICALAdobe Commerce | Improper Input Validation (CWE-20)EPSS 1.4%CVE-2021-32635MEDIUMAction Commands (run/shell/exec) Against Library URIs Ignore Configured Remote EndpointEPSS 1.4%CVE-2019-15262HIGHCisco Wireless LAN Controller Secure Shell Denial of Service VulnerabilityEPSS 1.4%CVE-2023-22888—Apache Airflow: Scheduler remote DoSEPSS 1.4%CVE-2021-25746HIGHIngress-nginx directive injection via annotationsEPSS 1.4%CVE-2019-1921MEDIUMCisco Email Security Appliance Content Filter Bypass VulnerabilityEPSS 1.4%CVE-2019-1955MEDIUMCisco Email Security Appliance Header Injection VulnerabilityEPSS 1.4%CVE-2020-7839HIGHMarkAny MaEPSBroker Command Injection VulnerabilityEPSS 1.4%CVE-2021-39234—Raw block data can be read bypassing ACL/authorizationEPSS 1.4%CVE-2022-42012MEDIUMAn issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can caEPSS 1.4%