Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2022-47378MEDIUMCODESYS: Multiple products prone to Improper Input ValidationEPSS 0.9%CVE-2026-27953HIGHormar has a Pydantic Validation Bypass via Kwargs Injection in Model ConstructorEPSS 0.9%CVE-2023-28099MEDIUMOpenSIPS has vulnerability in the ds_is_in_list() functionEPSS 0.9%CVE-2023-28098MEDIUMOpenSIPS has vulnerability in the Digest Authentication ParserEPSS 0.9%CVE-2023-26125MEDIUMVersions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a sEPSS 0.9%CVE-2023-46285HIGHA vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIEPSS 0.9%CVE-2022-0550HIGHAuthenticated RCE on logo report upload in Guardian/CMC before 22.0.0EPSS 0.9%CVE-2021-3624—There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code mEPSS 0.9%CVE-2022-0551HIGHAuthenticated RCE on project configuration import in Guardian/CMC before 22.0.0EPSS 0.9%CVE-2022-28695HIGHOn F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versionEPSS 0.9%CVE-2023-37915HIGHMalformed PID_PROPERTY_LIST parameter in DATA submessage remotely crashes OpenDDSEPSS 0.9%CVE-2026-44417HIGHApache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)EPSS 0.9%CVE-2024-50557HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.9%CVE-2024-49087MEDIUMWindows Mobile Broadband Driver Information Disclosure VulnerabilityEPSS 0.9%CVE-2023-32688MEDIUMInvalid push request payload crashes Parse ServerEPSS 0.9%CVE-2020-15191MEDIUMUndefined behavior in TensorflowEPSS 0.9%CVE-2023-46289HIGHRockwell Automation FactoryTalk® View Site Edition Vulnerable to Improper Input ValidationEPSS 0.9%CVE-2021-3583—A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the tEPSS 0.9%CVE-2019-12699HIGHCisco FXOS Software and Firepower Threat Defense Software Command Injection VulnerabilitiesEPSS 0.9%CVE-2023-20103MEDIUMCisco Secure Network Analytics Remote Code Execution VulnerabilityEPSS 0.9%