Weaknesses of type CWE-20

5,424 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2023-37548MEDIUMCODESYS: Improper Input Validation in CmpApp componentEPSS 0.6%CVE-2023-37559MEDIUMCODESYS Improper Validation of Consistency within Input in multiple productsEPSS 0.6%CVE-2023-37554MEDIUMCODESYS Improper Input Validation in CmpAppBPEPSS 0.6%CVE-2023-37546MEDIUMCODESYS: Improper Input Validation in CmpApp componentEPSS 0.6%CVE-2023-37552MEDIUMCODESYS Improper Input Validation in CmpAppBPEPSS 0.6%CVE-2023-37547MEDIUMCODESYS: Improper Input Validation in CmpApp componentEPSS 0.6%CVE-2023-37549MEDIUMCODESYS: Improper Input Validation in CmpApp componentEPSS 0.6%CVE-2023-37558MEDIUMCODESYS Improper Validation of Consistency within Input in multiple productsEPSS 0.6%CVE-2023-37556MEDIUMCODESYS Improper Input Validation in CmpAppBPEPSS 0.6%CVE-2026-46737MEDIUMDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high prEPSS 0.6%CVE-2023-37555MEDIUMCODESYS Improper Input Validation in CmpAppBPEPSS 0.6%CVE-2023-37553MEDIUMCODESYS Improper Input Validation in CmpAppBPEPSS 0.6%CVE-2024-45537MEDIUMApache Druid: Users can provide MySQL JDBC properties not on allow listEPSS 0.6%CVE-2023-37550MEDIUMCODESYS: Improper Input Validation in CmpApp componentEPSS 0.6%CVE-2023-47106MEDIUMIncorrect processing of fragment in the URL leads to Authorization Bypass in TraefikEPSS 0.6%CVE-2023-52296MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.6%CVE-2019-19095MEDIUMABB eSOMS: Stored XSS vulnerabilityEPSS 0.6%CVE-2018-0197—Cisco IOS and IOS XE Software VLAN Trunking Protocol Denial of Service VulnerabilityEPSS 0.6%CVE-2026-46592HIGHApache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operationEPSS 0.6%CVE-2026-55994HIGHApache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviourEPSS 0.6%