Falhas do tipo CWE-20

5.416 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2023-2727MEDIUMBypassing policies imposed by the ImagePolicyWebhook admission pluginEPSS 1.1%CVE-2026-20856HIGHWindows Server Update Service (WSUS) Remote Code Execution VulnerabilityEPSS 1.1%CVE-2019-15613—A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.EPSS 1.1%CVE-2025-34129HIGHLILIN DVR RCE via Malicious FTP/NTP ConfigurationEPSS 1.1%CVE-2022-46836CRITICALPHP code injection in watolibEPSS 1.1%CVE-2026-48316CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 1.1%CVE-2018-19945—Improper Limitation of a Pathname to a Restricted Directory in QTSEPSS 1.1%CVE-2021-32697MEDIUMForm validation can be skippedEPSS 1.1%CVE-2022-27655—When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version EPSS 1.1%CVE-2022-27654—When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versiEPSS 1.1%CVE-2023-22934HIGHSPL Command Safeguards Bypass via the ‘pivot’ SPL Command in Splunk EnterpriseEPSS 1.1%CVE-2023-3705HIGHInformation Disclosure Vulnerability in CP-Plus Network Video RecorderEPSS 1.1%CVE-2020-7518—A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modEPSS 1.1%CVE-2018-15429—Cisco HyperFlex HX Data Platform Software Unauthorized Directory Access VulnerabilityEPSS 1.1%CVE-2026-50632HIGHApache CXF: JNDI Injection Vulnerability in JMSConfigFactoryEPSS 1.1%CVE-2023-26281MEDIUMIBM HTTP Server denial of serviceEPSS 1.1%CVE-2022-21796CRITICALA memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A speciaEPSS 1.1%CVE-2023-48631MEDIUMDenial of Service of regular expression in package @adobe/css-toolsEPSS 1.1%CVE-2018-1110—A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.EPSS 1.1%CVE-2024-1481MEDIUMFreeipa: specially crafted http requests potentially lead to denial of serviceEPSS 1.1%