Weaknesses of type CWE-20

5,428 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-12128MEDIUMPinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' ParameterEPSS 0.6%CVE-2023-22491HIGHgatsby-transformer-remark vulnerable to unsanitized JavaScript code injection EPSS 0.6%CVE-2026-24406HIGHiccDEV has Heap Buffer Overflow in CIccTagNamedColor2::SetSize()EPSS 0.6%CVE-2026-24412HIGHiccDEV has Heap Buffer Overflow in icCurvesFromXml()EPSS 0.6%CVE-2025-27489HIGHAzure Local Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-24405HIGHiccDEV has Heap Buffer Overflow in CIccMpeCalculator::Read()EPSS 0.6%CVE-2022-45770HIGHImproper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.EPSS 0.6%CVE-2025-48490MEDIUMLaravel Rest Api has a Search Validation BypassEPSS 0.6%CVE-2024-28226HIGHFs has an improper input validation vulnerabilityEPSS 0.6%CVE-2022-23766HIGHBigFileAgent arbitrary file execution vulnerabilityEPSS 0.6%CVE-2023-36719HIGHMicrosoft Speech Application Programming Interface (SAPI) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-4287HIGHImproper Input Validation in mintplex-labs/anything-llmEPSS 0.6%CVE-2026-37460HIGHMissing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cauEPSS 0.6%CVE-2023-27984HIGHA CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to rEPSS 0.6%CVE-2026-49098MEDIUMApache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topicEPSS 0.6%CVE-2025-60938HIGHEmoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitraryEPSS 0.6%CVE-2021-27418MEDIUMGE UR family input validationEPSS 0.6%CVE-2026-59724HIGHSocket.IO: Engine.IO WebTransport SID DoSEPSS 0.6%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.6%CVE-2024-27092MEDIUMContent spoofing - real Hoppscotch emailsEPSS 0.6%