Falhas do tipo CWE-20

5.399 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2021-40127MEDIUMCisco Small Business 200, 300, and 500 Series Switches Web-Based Management Interface Denial of Service VulnerabilityEPSS 1.3%CVE-2020-3164MEDIUMCisco ESA, Cisco WSA, and Cisco SMA GUI Denial of Service VulnerabilityEPSS 1.3%CVE-2024-32007HIGHApache CXF Denial of Service vulnerability in JOSEEPSS 1.3%CVE-2024-38194HIGHAzure Web Apps Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2019-10937—A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to the device could causeEPSS 1.3%CVE-2022-21646HIGHLookup operations do not take into account wildcards in SpiceDBEPSS 1.3%CVE-2022-25271—Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validationEPSS 1.3%CVE-2025-30391HIGHMicrosoft Dynamics Information Disclosure VulnerabilityEPSS 1.3%CVE-2021-34736MEDIUMCisco Integrated Management Controller GUI Denial of Service VulnerabilityEPSS 1.3%CVE-2023-20009MEDIUMA vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) coEPSS 1.3%CVE-2022-39353CRITICALxmldom allows multiple root nodes in a DOMEPSS 1.3%CVE-2026-50633HIGHApache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImplEPSS 1.3%CVE-2021-26617HIGHGabia Firstmall remote code execution vulnerabilityEPSS 1.3%CVE-2018-19952—If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP SystEPSS 1.3%CVE-2026-75638MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 1.3%CVE-2024-5171CRITICALheap buffer overflow in libaomEPSS 1.3%CVE-2018-3776—Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit loEPSS 1.3%CVE-2023-35798—Airflow Apache ODBC and MSSQL Providers Arbitrary File Read VulnerabilityEPSS 1.3%CVE-2022-36058HIGHelrond-go MultiESDTNFTTransfer call on a SC address with missing function nameEPSS 1.3%CVE-2023-46116CRITICALRemote Code Execution via insufficiently sanitized call to shell.openExternalEPSS 1.3%