Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-46726HIGHApache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headersEPSS 0.9%CVE-2025-0465MEDIUMAquilaCMS categories deserializationEPSS 0.9%CVE-2018-1070MEDIUMrouting before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire sEPSS 0.9%CVE-2018-0475—Cisco IOS and IOS XE Software Cluster Management Protocol Denial of Service VulnerabilityEPSS 0.9%CVE-2023-45163CRITICAL1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code executionEPSS 0.9%CVE-2023-39530MEDIUMPrestaShop vulnerable to file deletion via CustomerMessageEPSS 0.9%CVE-2022-47392MEDIUMCODESYS: Multiple products prone to Improper Input ValidationEPSS 0.9%CVE-2024-31212MEDIUMSQL injection in index_chart_data actionEPSS 0.9%CVE-2022-47189HIGHDoS via file upload vulnerability at Generex CS141EPSS 0.9%CVE-2026-92860CRITICALrcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validationEPSS 0.9%CVE-2020-11007MEDIUMNegative charge in shopping cart possible in ShopizerEPSS 0.9%CVE-2025-24499HIGHA vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0EPSS 0.9%CVE-2020-15200MEDIUMSegfault in TensorflowEPSS 0.9%CVE-2025-69288CRITICALTitra has Remote Code Execution in Admin FunctionalityEPSS 0.9%CVE-2025-29847HIGHApache Linkis: Arbitrary File Read via Double URL Encoding BypassEPSS 0.9%CVE-2024-38105MEDIUMWindows Layer-2 Bridge Network Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2023-42802CRITICALGLPI vulnerable to unallowed PHP script executionEPSS 0.8%CVE-2024-25016HIGHIBM MQ denial of serviceEPSS 0.8%CVE-2023-30991HIGHIBM Db2 denial of serviceEPSS 0.8%CVE-2023-33182NONENextcloud Contacts photos only sanitized if mime type is all lower caseEPSS 0.8%