Falhas do tipo CWE-20

5.416 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2024-11234MEDIUMConfiguring a proxy in a stream context might allow for CRLF injection in URIsEPSS 1.1%CVE-2020-1656HIGHJunos OS: When a DHCPv6 Relay-Agent is configured upon receipt of a specific DHCPv6 client message, Remote Code Execution may occur.EPSS 1.1%CVE-2020-27823—A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during enEPSS 1.1%CVE-2020-7862HIGHHelpU Overflow VulnerabilityEPSS 1.1%CVE-2019-1798HIGHClam AntiVirus PE File Out-of-Bounds Read VulnerabilityEPSS 1.1%CVE-2023-47701MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2023-24893HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 1.1%CVE-2022-36023HIGHRemote denial of service in Hyperledger Fabric GatewayEPSS 1.1%CVE-2016-8631MEDIUMThe OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routesEPSS 1.1%CVE-2021-1524MEDIUMCisco Meeting Server API Denial of Service VulnerabilityEPSS 1.1%CVE-2021-42120MEDIUMMissing Character Length (Denial of Service) in TopEaseEPSS 1.1%CVE-2025-64989HIGHCommand Injection in 1E-Explorer-TachyonCore-FindFileBySizeAndHash InstructionEPSS 1.1%CVE-2025-30452CRITICALThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An inputEPSS 1.1%CVE-2018-15387—Cisco SD-WAN Solution Certificate Validation Bypass VulnerabilityEPSS 1.1%CVE-2020-3479MEDIUMCisco IOS and IOS XE Software MP-BGP EVPN Denial of Service VulnerabilityEPSS 1.1%CVE-2020-12033—In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied idEPSS 1.1%CVE-2022-1302HIGHMalformed Goose Message in LibIEC61850 may result in a denial of serviceEPSS 1.1%CVE-2022-46303HIGHCommand injection in SMS notificationsEPSS 1.1%CVE-2019-16762MEDIUMValidator parsing discrepancy due to string encoding in NPM slpjsEPSS 1.1%CVE-2026-1771HIGHMapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' EndpointEPSS 1.1%