Falhas do tipo CWE-20

5.399 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-40518HIGHSeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the useEPSS 1.2%CVE-2021-25745HIGHIngress-nginx path can be pointed to service account token fileEPSS 1.2%CVE-2020-25151—The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack on the NIO 50 (all EPSS 1.2%CVE-2017-12299—A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall ServEPSS 1.2%CVE-2021-1465MEDIUMA vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to condEPSS 1.2%CVE-2025-64987HIGHCommand Injection in 1E-Explorer-TachyonCore-CheckSimpleIoC InstructionEPSS 1.2%CVE-2022-44644MEDIUMApache Linkis (incubating): The DatasourceManager module has a Local File Read VulnerabilityEPSS 1.2%CVE-2024-34365CRITICALApache Karaf Cave: Cave SSRF and arbitrary file accessEPSS 1.2%CVE-2025-64988HIGHCommand Injection in 1E-Nomad-GetCmContentLocations InstructionEPSS 1.2%CVE-2026-4987HIGHSureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'EPSS 1.2%CVE-2021-36335MEDIUMDell EMC CloudLink 7.1 and all prior versions contain an Improper Input Validation Vulnerability. A remote low privileged attacker, may poteEPSS 1.2%CVE-2021-3567—A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applicationsEPSS 1.2%CVE-2022-25940HIGHDenial of Service (DoS)EPSS 1.2%CVE-2020-3567MEDIUMCisco Industrial Network Director Denial of Service VulnerabilityEPSS 1.2%CVE-2020-8475MEDIUMABB Central Licensing System - Denial of Service VulnerabilityEPSS 1.2%CVE-2023-26364MEDIUMDenial of Service of regular expression in package @adobe/css-toolsEPSS 1.2%CVE-2019-15966HIGHA vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause aEPSS 1.2%CVE-2017-1002153—Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.EPSS 1.2%CVE-2021-42857MEDIUMDirectory Traversal Partial Write at AgentDaServletEPSS 1.1%CVE-2026-41044HIGHApache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by JolokiaEPSS 1.1%