Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2022-0567—A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bEPSS 1.0%CVE-2022-22539—When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versionEPSS 1.0%CVE-2021-30501—An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of servEPSS 1.0%CVE-2018-10921MEDIUMCertain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially lead to corruption of EPSS 1.0%CVE-2021-26631HIGHMangboard parameter modulation vulnerabilityEPSS 1.0%CVE-2026-45495HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-75634MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 1.0%CVE-2026-76194MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 1.0%CVE-2021-20330MEDIUMSpecific replication command with malformed oplog entries can crash secondariesEPSS 1.0%CVE-2021-22787HIGHA CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a speciallyEPSS 1.0%CVE-2023-5188HIGHWAGO Improper Input Validation in IEC61850 Server / TelecontrolEPSS 1.0%CVE-2026-20224HIGHCisco Catalyst SD-WAN Manager XML External Entity Injection VulnerabilityEPSS 1.0%CVE-2024-26181MEDIUMWindows Kernel Denial of Service VulnerabilityEPSS 1.0%CVE-2013-4144—There is an object injection vulnerability in swfupload plugin for wordpress.EPSS 1.0%CVE-2021-42121MEDIUMDenial of Service via Invalid Date Format in TopEaseEPSS 1.0%CVE-2021-1221MEDIUMCisco Webex Meetings and Cisco Webex Meetings Server Software Hyperlink Injection VulnerabilityEPSS 1.0%CVE-2024-20684MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 1.0%CVE-2021-22678—Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory EPSS 1.0%CVE-2024-0710MEDIUMGP Unique ID <= 1.5.5 - Unauthenticated Form Submission Unique ID ModificationEPSS 1.0%CVE-2020-2504MEDIUMAbsolute path traversal vulnerability in QESEPSS 1.0%