Weaknesses of type CWE-670
101 resultsValidação inadequada de entrada
A aplicação aceita dados do usuário sem verificar se estão no formato, tamanho ou tipo esperado, permitindo que valores malformados ou maliciosos sejam processados. Isso abre porta para injeção, estouro de buffer, lógica corrompida e outros ataques.
Example
Um formulário web que recebe um CPF sem verificar se contém apenas dígitos, ou que aceita um campo 'idade' como string sem validar se é um número positivo. Um atacante envia valores inesperados (SQL injection, scripts) que a aplicação processa como legítimos.
How to mitigate
Implemente validação em todos os pontos de entrada: whitelist de caracteres permitidos, limites de tamanho, tipagem explícita, e rejeite dados que não correspondam ao esperado. Valide tanto no cliente (UX) quanto no servidor (segurança).
CVE-2024-35190MEDIUMAsterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requestsEPSS 0.6%CVE-2022-39354MEDIUMevm has incorrect is_static parameter for custom stateful precompilesEPSS 0.6%CVE-2022-2993HIGHbt: host: Wrong key validation checkEPSS 0.6%CVE-2023-32675LOWNonpayable default functions are sometimes payable in vyperEPSS 0.6%CVE-2026-55276CRITICALApache Tomcat: Logged effective web.xml is incompleteEPSS 0.5%CVE-2023-49798MEDIUMDuplicated execution of subcalls in OpenZeppelin ContractsEPSS 0.5%CVE-2022-31017LOWExpression Always True vulnerability in Zulip ServerEPSS 0.5%CVE-2023-41338MEDIUMVulnerability in Ctx.IsFromLocal() in gofiberEPSS 0.5%CVE-2024-45807HIGHoghttp2 crash on OnBeginHeadersForStream in envoyEPSS 0.5%CVE-2024-45304MEDIUMOwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ownership in cairo-contractsEPSS 0.5%CVE-2021-43819HIGHStargate-Bukkit improperly handles vehicles causing data duplication.EPSS 0.5%CVE-2026-20171MEDIUMCisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service VulnerabilityEPSS 0.5%CVE-2023-41052LOWVyper: incorrect order of evaluation of side effects for some builtinsEPSS 0.5%CVE-2025-29312CRITICALAn issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link tEPSS 0.5%CVE-2025-32996MEDIUMIn http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.EPSS 0.4%CVE-2024-25622LOWH2O ignores headers configuration directivesEPSS 0.4%CVE-2026-1874HIGHDenial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module and Ethernet moduleEPSS 0.4%CVE-2023-40015LOWVyper: reversed order of side effects for some operationsEPSS 0.4%CVE-2023-0400MEDIUM
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP contEPSS 0.4%CVE-2022-25745CRITICALAlways Incorrect Control Flow Implementation in MODEMEPSS 0.4%