Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2018-12448—Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-htEPSS 0.8%CVE-2022-36027MEDIUMSegfault TFLite converter on per-channel quantized transposed convolutions in TensorFlowEPSS 0.8%CVE-2022-31170HIGH OpenZeppelin Contracts's ERC165Checker may revert instead of returning falseEPSS 0.8%CVE-2024-23641HIGHSending a GET or HEAD request with a body crashes SvelteKitEPSS 0.8%CVE-2024-25131HIGHOpenshift-dedicated: must-gather-operator: yaml template injection leads to privilege escalationEPSS 0.8%CVE-2023-4043MEDIUMParsson DoS when parsing numbers from untrusted sourcesEPSS 0.8%CVE-2023-46929HIGHAn issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:EPSS 0.8%CVE-2025-54365HIGHfastapi-guard patch contains bypassable RegExEPSS 0.8%CVE-2021-41250MEDIUMPresence of non-blacklisted URL bypasses all other filtersEPSS 0.8%CVE-2021-39230HIGHError in JPNS kernel of ButterEPSS 0.8%CVE-2023-32075MEDIUMPimcore vulnerable to Business Logic Errors in Customer automation rulesEPSS 0.8%CVE-2024-38243HIGHKernel Streaming Service Driver Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2017-3849—A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and CiEPSS 0.8%CVE-2022-33876MEDIUMMultiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.EPSS 0.8%CVE-2026-26314HIGHGo Ethereum affected by DoS via malicious p2p messageEPSS 0.8%CVE-2023-32890MEDIUMIn modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additioEPSS 0.8%CVE-2022-39306MEDIUMGrafana contains Improper Input ValidationEPSS 0.8%CVE-2025-27737HIGHWindows Security Zone Mapping Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2024-52802HIGHRIOT-OS missing dhcpv6_opt_t minimum header length checkEPSS 0.8%CVE-2023-49551HIGHAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.EPSS 0.8%