Weaknesses of type CWE-20

5,418 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2022-43919MEDIUMIBM MQ denial of serviceEPSS 0.7%CVE-2026-22862HIGHgo-ethereum has a DoS via malicious p2p messageEPSS 0.7%CVE-2023-26070CRITICALCertain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).EPSS 0.7%CVE-2023-31009HIGHNVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploiEPSS 0.7%CVE-2017-12275—A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wireless LAN ControlleEPSS 0.7%CVE-2023-26069CRITICALCertain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).EPSS 0.7%CVE-2026-27928HIGHWindows Hello Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2022-30233MEDIUMA CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when the user is trickedEPSS 0.7%CVE-2026-21548HIGHIn nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges neeEPSS 0.7%CVE-2026-21554HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.7%CVE-2026-21549HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.7%CVE-2026-21553HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.7%CVE-2026-21550HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.7%CVE-2026-28894HIGHA denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.EPSS 0.7%CVE-2022-3181HIGHAn Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request coulEPSS 0.7%CVE-2026-21551HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.7%CVE-2025-57810HIGHjsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)EPSS 0.7%CVE-2026-21552HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.7%CVE-2026-21555HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegesEPSS 0.7%CVE-2022-4033MEDIUMQuiz and Survey Master <= 8.0.4 - Improper Input ValidationEPSS 0.7%