Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2023-40373MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2024-44809CRITICALA remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from imprEPSS 0.8%CVE-2020-7867HIGHHelpu arbitrary file creation vulnerabilityEPSS 0.8%CVE-2017-12274—A vulnerability in Extensible Authentication Protocol (EAP) ingress frame processing for the Cisco Aironet 1560, 2800, and 3800 Series AccesEPSS 0.8%CVE-2026-24936CRITICALAn improper input validation vulnerability was found in ADM while joining a AD Domain.EPSS 0.8%CVE-2026-66793HIGHGovernance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via managedclusteraddon annotation enables rce on spokeEPSS 0.8%CVE-2025-54306HIGHAn issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the neEPSS 0.8%CVE-2020-10622—LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized usersEPSS 0.8%CVE-2023-45193MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2026-0848CRITICALArbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR LoadingEPSS 0.8%CVE-2023-47161MEDIUMIBM UrbanCode Deploy denial of serviceEPSS 0.8%CVE-2024-38355HIGHUnhandled 'error' event in socket.ioEPSS 0.8%CVE-2021-31373HIGHJunos OS: SRX Series: Persistent XSS vulnerability in J-WebEPSS 0.8%CVE-2024-43540MEDIUMWindows Mobile Broadband Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2023-21749HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-43542MEDIUMWindows Mobile Broadband Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2026-33844CRITICALAzure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-43538MEDIUMWindows Mobile Broadband Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2022-41214HIGHDue to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges EPSS 0.8%CVE-2024-31841HIGHAn issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to EPSS 0.8%