Weaknesses of type CWE-20

5,418 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2023-27488MEDIUMEnvoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.EPSS 0.7%CVE-2024-3029CRITICALImproper Input Validation in mintplex-labs/anything-llmEPSS 0.7%CVE-2026-22444HIGHApache Solr: Insufficient file-access checking in standalone core-creation requestsEPSS 0.7%CVE-2025-2622MEDIUMaizuda snail-job Workflow-Task Management Module check-node-expression getRuntime deserializationEPSS 0.7%CVE-2026-48769CRITICALIncus has an arbitrary file write on its client due to trusted image hashEPSS 0.7%CVE-2022-32236—When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the apEPSS 0.7%CVE-2024-26253MEDIUMWindows rndismp6.sys Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-3841HIGHInsufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTMLEPSS 0.7%CVE-2021-42117LOWUI Redressing in TopEaseEPSS 0.7%CVE-2019-15997MEDIUMCisco DNA Spaces: Connector Command Injection VulnerabilityEPSS 0.7%CVE-2025-4377HIGHPath traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.phpEPSS 0.7%CVE-2022-29492MEDIUMA vulnerability exists in the handling of a malformed IEC 104 TCP packet. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TCP connection is left open. This may cause a denial-of-service if the affected conne ...EPSS 0.7%CVE-2022-22508MEDIUMCODESYS V3: Improper Input ValidationEPSS 0.7%CVE-2023-24493MEDIUMA formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An auEPSS 0.7%CVE-2023-32305HIGHaiven-extras PostgreSQL Privilege Escalation Through Overloaded Search PathEPSS 0.7%CVE-2021-27760MEDIUMHCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats loading script on restartEPSS 0.7%CVE-2022-27674HIGHInsufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to aEPSS 0.7%CVE-2024-22027MEDIUMImproper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a EPSS 0.7%CVE-2020-3429HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WPA Denial of Service VulnerabilityEPSS 0.7%CVE-2020-15197MEDIUMDenial of Service in TensorflowEPSS 0.7%