Falhas do tipo CWE-20

5.418 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2023-27496MEDIUMEnvoy may crash when a redirect url without a state param is received in the oauth filterEPSS 0.8%CVE-2023-48608LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.8%CVE-2021-25444—An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.EPSS 0.8%CVE-2022-4032HIGHQuiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short AnswerEPSS 0.8%CVE-2022-31772MEDIUMIBM MQ denial of serviceEPSS 0.8%CVE-2023-36406MEDIUMWindows Hyper-V Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-45062HIGHFrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP FilesEPSS 0.8%CVE-2026-44300HIGHOpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/InjectionEPSS 0.8%CVE-2023-32728MEDIUMCode injection in zabbix_agent2 smart.disk.get caused by smartctl pluginEPSS 0.8%CVE-2022-3767HIGHMissing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every EPSS 0.8%CVE-2024-25090MEDIUMApache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users modeEPSS 0.8%CVE-2016-9494—Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation, potentially leading to denial of serviceEPSS 0.8%CVE-2025-26413HIGHApache Kvrocks: The server was crashed by the negative offsetEPSS 0.8%CVE-2026-53503HIGHThumbor convolution filter allows divide-by-zero in C extension leading to remote DoSEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2021-29507MEDIUMdlt-daemon could crash if there is special character in dlt.confEPSS 0.7%CVE-2025-62222HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-93567HIGHIo.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authorityEPSS 0.7%CVE-2022-29562LOWA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 0.7%CVE-2024-23483HIGHLocal Privilege Escalation via lack of input validationEPSS 0.7%