Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-21234HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2021-1383MEDIUMCisco IOS XE SD-WAN Software Parameter Injection VulnerabilitiesEPSS 0.6%CVE-2026-45556CRITICALRoxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`EPSS 0.6%CVE-2026-42812CRITICALApache Polaris: No protection on `write.metadata.path`EPSS 0.6%CVE-2024-35227HIGHDiscourse vulnerable to DoS through OneboxEPSS 0.6%CVE-2026-55068CRITICALfree5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpointsEPSS 0.6%CVE-2025-4613HIGHClient side RCE in Google Web Designer AppEPSS 0.6%CVE-2023-25650MEDIUMArbitrary File Download Vulnerability in ZTE ZXCLOUD iRAIEPSS 0.6%CVE-2023-32170MEDIUMUnified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service VulnerabilityEPSS 0.6%CVE-2026-63621MEDIUMApache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategyEPSS 0.6%CVE-2026-61794MEDIUMCapsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panicEPSS 0.6%CVE-2022-43455MEDIUMCVE-2022-43455EPSS 0.6%CVE-2023-22939HIGHSPL Command Safeguards Bypass via the ‘map’ SPL Command in Splunk EnterpriseEPSS 0.6%CVE-2025-22137CRITICALArbitrary File Overwrite via HTTP POST in Pingvin ShareEPSS 0.6%CVE-2026-5388CRITICALjusthtml before 1.15.0 Multiple Security IssuesEPSS 0.6%CVE-2026-81707CRITICALopenssl_encrypt before 1.4.9 ANSI Escape Injection via Identity EmailEPSS 0.6%CVE-2026-7808CRITICALjusthtml before 1.16.0 Multiple Security Issues via SanitizationEPSS 0.6%CVE-2023-29134HIGHAn issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.EPSS 0.6%CVE-2025-29811HIGHWindows Mobile Broadband Driver Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-23998MEDIUMImproper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in AEPSS 0.6%