Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2017-3180—Multiple TIBCO Spotfire components fail to sanitize user-supplied inout and are vulnerable to cross-site scriptingEPSS 0.6%CVE-2023-33042HIGHImproper Input Validation in ModemEPSS 0.6%CVE-2025-10771MEDIUMjeecgboot JimuReport DB2 JDBC testConnection deserializationEPSS 0.6%CVE-2026-50540CRITICALKata Containers: Config Path Annotation Arbitrary File LoadingEPSS 0.6%CVE-2019-18994LOWABB PB610 HMIStudio crashes after launching an empty *.JPR application fileEPSS 0.6%CVE-2019-1846HIGHCisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers MPLS OAM Denial of Service VulnerabilityEPSS 0.6%CVE-2019-1749HIGHCisco Aggregation Services Router 900 Route Switch Processor 3 OSPFv2 Denial of Service VulnerabilityEPSS 0.6%CVE-2025-34021HIGHSelea Targa IP OCR-ANPR Camera Server-Side Request ForgeryEPSS 0.6%CVE-2025-59537HIGHargo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payloadEPSS 0.6%CVE-2021-42856MEDIUMReflected Cross-site Scripting at DsaDataTestEPSS 0.6%CVE-2023-29455MEDIUMReflected XSS in several fields of graph formEPSS 0.6%CVE-2026-4342HIGHingress-nginx comment-based nginx configuration injectionEPSS 0.6%CVE-2017-12334—A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attackEPSS 0.6%CVE-2024-56135HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2024-56133HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2026-33267HIGHApache Traffic Server: Untrusted @ headers can spoof ATS internal metadataEPSS 0.6%CVE-2023-22734MEDIUMImproper Input Newsletter subscription option validation in shopwareEPSS 0.6%CVE-2024-56134HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2023-42503—Apache Commons Compress: Denial of service via CPU consumption for malformed TAR fileEPSS 0.6%CVE-2024-21549HIGHVersions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the seEPSS 0.6%