Weaknesses of type CWE-20

5,421 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2022-32242—When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, theEPSS 0.7%CVE-2023-32037MEDIUMWindows Layer-2 Bridge Network Driver Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-36392HIGHImproper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94,EPSS 0.7%CVE-2021-34597HIGHPhoenix Contact: PC Worx/-Express prone to improper input validation vulnerabilityEPSS 0.7%CVE-2025-8227MEDIUMyanyutao0402 ChanCMS getArticle deserializationEPSS 0.7%CVE-2026-27623HIGHValkey has Pre-Authentication DOS from malformed RESP requestEPSS 0.7%CVE-2023-36860HIGHImproper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via nEPSS 0.7%CVE-2024-27254MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.7%CVE-2024-22360MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.7%CVE-2024-25046MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.7%CVE-2026-3644MEDIUMIncomplete control character validation in http.cookiesEPSS 0.7%CVE-2024-49753MEDIUMDenied Host Validation Bypass in Zitadel ActionsEPSS 0.7%CVE-2023-3724CRITICALTLS 1.3 client issue handling malicious server when not including a KSE and PSK extensionEPSS 0.7%CVE-2024-4609HIGHRockwell Automation Datalog Function within in FactoryTalk® View SE contains SQL Injection VulnerabilityEPSS 0.7%CVE-2022-2232HIGHKeycloak: ldap injection on username inputEPSS 0.7%CVE-2022-40235MEDIUM"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper EPSS 0.7%CVE-2026-19480HIGHCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.7%CVE-2023-34239HIGHUnfiltered paths in gradioEPSS 0.7%CVE-2025-31217MEDIUMThe issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS SEPSS 0.7%CVE-2026-27642MEDIUMfree5GC has Improper Input Validation in UDM UEAU ServiceEPSS 0.7%