Falhas do tipo CWE-20

5.399 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2019-19337MEDIUMA flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker cEPSS 1.3%CVE-2023-24807HIGHUndici vulnerable to Regular Expression Denial of Service in HeadersEPSS 1.3%CVE-2020-15170HIGHMissing access control in apollo-adminserviceEPSS 1.3%CVE-2021-3970MEDIUMA potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attaEPSS 1.3%CVE-2020-8568MEDIUMKubernetes Secrets Store CSI Driver sync/rotate directory traversalEPSS 1.3%CVE-2022-20679MEDIUMCisco IOS XE Software IPSec Denial of Service VulnerabilityEPSS 1.3%CVE-2019-12706MEDIUMCisco Email Security Appliance Filter Bypass VulnerabilityEPSS 1.3%CVE-2022-29897CRITICALRemote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACTEPSS 1.3%CVE-2023-24816MEDIUMset_term_title command injection in ipythonEPSS 1.3%CVE-2017-12701—BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authentEPSS 1.3%CVE-2022-47192HIGHAdmin password reset via file upload vulnerability in Generex CS141EPSS 1.3%CVE-2018-1051—It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possibleEPSS 1.3%CVE-2023-48693HIGHAzure RTOS ThreadX Remote Code Execution VulnerabilityEPSS 1.3%CVE-2021-3910MEDIUMNUL character in ROA causes OctoRPKI to crashEPSS 1.3%CVE-2021-1305HIGHCisco SD-WAN vManage Authorization Bypass VulnerabilitiesEPSS 1.3%CVE-2022-24846CRITICALUnchecked JNDI lookups in GeoWebCacheEPSS 1.3%CVE-2026-48277CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 1.3%CVE-2017-2674MEDIUMJBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sEPSS 1.3%CVE-2025-31208HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS SonoEPSS 1.3%CVE-2026-77539CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS EPSS 1.3%