Weaknesses of type CWE-20

5,418 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-1177MEDIUMdayrui XunRuiCMS Linkage.php import_add deserializationEPSS 0.7%CVE-2025-1701HIGHLocal Privilege Escalation in MIM Admin ServiceEPSS 0.7%CVE-2020-7870MEDIUMA memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validatiEPSS 0.7%CVE-2024-45258CRITICALThe req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionEPSS 0.7%CVE-2022-45088CRITICALLocal File Inclusion in Smartpower WebEPSS 0.7%CVE-2026-42811CRITICALApache Polaris: could broaden vended GCS credentials through unescaped identifier content in access-boundary CEL conditionsEPSS 0.7%CVE-2023-50709MEDIUMDenial of service attack on the cube-api endpointEPSS 0.7%CVE-2023-27586CRITICALCairoSVG improperly processes SVG files loaded from external resourcesEPSS 0.7%CVE-2025-30213MEDIUMFrappe has Possibility of Remote Code Execution due to improper validationEPSS 0.7%CVE-2024-20721MEDIUMT5 Acrobat JS vulnerability - Exploitable crash via t5::javascript::get_page_num_wordsEPSS 0.7%CVE-2026-57985HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-34851MEDIUMBIG-IP and BIG-IQ iControl SOAP vulnerability CVE-2022-34851EPSS 0.7%CVE-2024-21519MEDIUMThis affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restorEPSS 0.7%CVE-2026-54632HIGHSIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)EPSS 0.7%CVE-2021-22538MEDIUMPrivilege escalation in RBAC systemEPSS 0.7%CVE-2026-44522HIGHNote Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code ExecutionEPSS 0.7%CVE-2026-48436MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.7%CVE-2024-25290HIGHAn issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.EPSS 0.7%CVE-2026-73513HIGHEnvoy: oghttp2 upstream trailers incorrect handlingEPSS 0.7%CVE-2023-50256HIGHFroxlor username/surname AND company field BypassEPSS 0.7%