Weaknesses of type CWE-20

5,418 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2019-13939HIGHA vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3),EPSS 0.7%CVE-2022-4427MEDIUMSQL Injection via OTRS Search APIEPSS 0.7%CVE-2026-44180CRITICALJupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be BypassedEPSS 0.7%CVE-2023-41268MEDIUMPossible stack overflow due to insufficient input validationEPSS 0.7%CVE-2022-21696MEDIUMUsername spoofing in OnionShareEPSS 0.7%CVE-2022-41733MEDIUMIBM InfoSphere Information Server denial of serviceEPSS 0.7%CVE-2023-39529MEDIUMPrestaShop vulnerable to file deletion via attachment APIEPSS 0.7%CVE-2019-1750HIGHCisco IOS XE Software Catalyst 4500 Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.7%CVE-2026-3288HIGHingress-nginx rewrite-target nginx configuration injectionEPSS 0.7%CVE-2021-44462HIGHHorner Automation Cscape EnvisionRV Improper Input ValidationEPSS 0.7%CVE-2023-32690MEDIUMResponder can Invoke Undefined Behavior in libspdm RequesterEPSS 0.7%CVE-2022-43908MEDIUMIBM Security Guardium denial of serviceEPSS 0.7%CVE-2023-22581CRITICALWhite Rabbit Switch - Unauthenticated remote code executionEPSS 0.7%CVE-2022-43903MEDIUMIBM Security Guardium denial of serviceEPSS 0.7%CVE-2025-47282CRITICALMalicious google credential in DNS secret can lead to privilege escalationEPSS 0.7%CVE-2023-38131MEDIUMImproper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via neEPSS 0.7%CVE-2023-41917CRITICALImproper input validation in Kiloview P1/P2 devices allows for remote code executionEPSS 0.7%CVE-2023-32485CRITICAL Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attackEPSS 0.7%CVE-2014-125114HIGHi-Ftp 2.20 Schedule.xml Stack-Based Buffer OverflowEPSS 0.7%CVE-2022-43919MEDIUMIBM MQ denial of serviceEPSS 0.7%