Falhas do tipo CWE-20

5.416 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-93952CRITICALSecurity Advisory 0183EPSS 0.9%KEVCVE-2021-40365HIGHAffected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a deniEPSS 0.9%CVE-2022-29257MEDIUMElectron's AutoUpdater module fails to validate certain nested components of the bundleEPSS 0.9%CVE-2023-0359MEDIUMipv6: Missing ipv6 nullptr-check in handle_ra_inputEPSS 0.9%CVE-2024-26173HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2024-55952HIGHDataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE VulnerabilityEPSS 0.9%CVE-2025-43347CRITICALThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26,EPSS 0.9%CVE-2024-38311MEDIUMApache Traffic Server: Request smuggling via pipelining after a chunked message bodyEPSS 0.9%CVE-2021-37707MEDIUMManipulation of product reviews via APIEPSS 0.9%CVE-2024-45798CRITICALMultiple Poisoned Pipeline Execution (PPE) vulnerabilitiesEPSS 0.9%CVE-2022-38778MEDIUMA flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a requEPSS 0.9%CVE-2020-1676HIGHJuniper Networks Mist Cloud UI: SAML authentication response handling vulnerability.EPSS 0.9%CVE-2022-4504HIGHImproper Input Validation in openemr/openemrEPSS 0.9%CVE-2022-26108—When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versionEPSS 0.9%CVE-2022-22537—When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise ViewerEPSS 0.9%CVE-2023-34317MEDIUMAn improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18EPSS 0.9%CVE-2026-45505HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper BypassEPSS 0.9%CVE-2023-40034HIGHRepositoty takeover in woodpecker-ciEPSS 0.9%CVE-2025-63213CRITICALThe QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validatiEPSS 0.9%CVE-2023-49081HIGHaiohttp's ClientSession is vulnerable to CRLF injection via versionEPSS 0.9%