Weaknesses of type CWE-20

5,421 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-54909MEDIUMPion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attributeEPSS 0.6%CVE-2026-5329HIGHRapid7 Velociraptor Improper Input Validation in Client Message HandlerEPSS 0.6%CVE-2026-56340HIGHvLLM - Denial of Service via Unvalidated Multimodal EmbeddingsEPSS 0.6%CVE-2023-5571MEDIUMImproper Input Validation in vriteio/vriteEPSS 0.6%CVE-2026-7803CRITICALFlow Validation Bypass via Empty Component Type FieldEPSS 0.6%CVE-2019-1746HIGHCisco IOS and IOS XE Software Cluster Management Protocol Denial of Service VulnerabilityEPSS 0.6%CVE-2026-1315HIGHUnauthenticated Denial of Service via Firmware Update Endpoint on TP-Link Tapo C220 & C520WSEPSS 0.6%CVE-2019-1816MEDIUMCisco Web Security Appliance Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-53652HIGHJenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches oEPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%CVE-2022-3676MEDIUMIn Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of tEPSS 0.6%CVE-2026-93295HIGHMISP Background Job Argument Injection via Console Path Switches Enables Remote Code ExecutionEPSS 0.6%CVE-2026-39386HIGHNeko has Self-service Privilege Escalation for Authenticated UsersEPSS 0.6%CVE-2023-31013MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploiEPSS 0.6%CVE-2023-31012MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploitEPSS 0.6%CVE-2024-21315HIGHMicrosoft Defender for Endpoint Protection Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2020-3390HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Trap Denial of Service VulnerabilityEPSS 0.6%CVE-2025-61920HIGHAuthlib is vulnerable to Denial of Service via Oversized JOSE SegmentsEPSS 0.6%CVE-2023-48311HIGHAny image allowed by defaultEPSS 0.6%CVE-2023-28113MEDIUMrussh may use insecure Diffie-Hellman keysEPSS 0.6%