Falhas do tipo CWE-670

110 resultados

Validação inadequada de entrada

A aplicação aceita dados do usuário sem verificar corretamente se estão no formato, tamanho ou conteúdo esperado antes de usá-los. Isso permite que entradas malformadas ou maliciosas causem comportamentos inesperados, desde injeção de código até travamentos.

Exemplo

Um formulário web que recebe um CPF não valida o formato (deve ter 11 dígitos) e passa direto para a query SQL. Um atacante injeta comando SQL disfarçado de CPF, ou um campo de data aceita strings arbitrárias e quebra a lógica de cálculo da aplicação.

Como mitigar

Implemente whitelist de caracteres permitidos, valide tipo e tamanho na entrada, use prepared statements para SQL, e trate erros sem expor detalhes internos. Nunca confie em dados do cliente, mesmo que venham de JavaScript — valide sempre no servidor.

CVE-2023-0400MEDIUM The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP contEPSS 0.4%CVE-2026-48844HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could leaEPSS 0.4%CVE-2024-45298MEDIUMDisabled user can bypass lockout by requesting password reset in wiki.jsEPSS 0.4%CVE-2026-32713MEDIUMPX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File DescriptorsEPSS 0.4%CVE-2026-40719HIGHDeadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolvEPSS 0.4%CVE-2026-56307MEDIUMCap-go - Broken Cursor Pagination in /private/devices EndpointEPSS 0.4%CVE-2026-16392CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2026-34946MEDIUMWasmtime's host panics when Winch compiler executes `table.fill`EPSS 0.4%CVE-2022-41884MEDIUMSeg fault in `ndarray_tensor_bridge` due to zero and large inputs in TensorflowEPSS 0.4%CVE-2026-56328HIGHCapgo - Integrity Issue in Release Routing via Multiple Public ChannelsEPSS 0.3%CVE-2026-40396MEDIUMVarnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could sEPSS 0.3%CVE-2026-33011HIGHNest Fastify HEAD Request Middleware BypassEPSS 0.3%CVE-2024-35195MEDIUMRequests `Session` object does not verify requests after making first request with verify=FalseEPSS 0.3%CVE-2024-47168LOWThe `enable_monitoring` flag set to `False` does not disable monitoring in GradioEPSS 0.3%CVE-2026-7656HIGHBroken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stackEPSS 0.3%CVE-2026-26267HIGHrs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collideEPSS 0.3%CVE-2025-2886MEDIUMTerminating targets role delegations are not respected in toughEPSS 0.3%CVE-2025-24800CRITICALCritical vulnerability in `ismp-grandpa` <v15.0.1EPSS 0.3%CVE-2024-5659HIGHRockwell Automation Multicast Request Causes major nonrecoverable fault on Select ControllersEPSS 0.3%CVE-2026-6608MEDIUMlm-sys fastchat Arena Side-by-Side View add_text control flowEPSS 0.3%