Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2022-47191MEDIUMPrivilege Escalation via file upload vulnerability at Generex CS141EPSS 1.1%CVE-2024-38033HIGHPowerShell Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2019-10134MEDIUMA flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly EPSS 1.1%CVE-2022-39361HIGHMetabase vulnerable to Remote Code Execution via H2EPSS 1.1%CVE-2023-38727MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2023-29258MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2023-40687MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2022-24806MEDIUMnet-snmp vulnerable to Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneouslyEPSS 1.1%CVE-2024-20003HIGHIn Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent EPSS 1.1%CVE-2023-32695HIGHInsufficient validation when decoding a Socket.IO packetEPSS 1.1%CVE-2026-22563CRITICALA series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play netEPSS 1.1%CVE-2021-26605HIGHunidocs ezPDFReader arbitrary command execution vulnerabilityEPSS 1.0%CVE-2024-36053CRITICALIn the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in checEPSS 1.0%CVE-2023-51747HIGHSMTP smuggling in Apache JamesEPSS 1.0%CVE-2020-1672HIGHJunos OS: jdhcpd process crash when processing a specific DHCPDv6 packet in DHCPv6 relay configuration.EPSS 1.0%CVE-2026-26147HIGHAzure Stack HCI Information Disclosure VulnerabilityEPSS 1.0%CVE-2022-39318MEDIUMDivision by zero in urbdrc channel in FreeRDPEPSS 1.0%CVE-2020-3139MEDIUMCisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass VulnerabilityEPSS 1.0%CVE-2019-13932—A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the appEPSS 1.0%CVE-2023-25915CRITICALAuthenticated Remote Command Execution in Danfoss AK-SM800AEPSS 1.0%