Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-54204HIGHTeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionalityEPSS 0.6%CVE-2023-0683HIGHA valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.EPSS 0.6%CVE-2023-33964HIGHmx-chain-go does not treat invalid transaction with wrong username correctlyEPSS 0.6%CVE-2025-6279MEDIUMUpsonic Pickle add_tool cloudpickle.loads deserializationEPSS 0.6%CVE-2020-15201MEDIUMHeap buffer overflow in TensorflowEPSS 0.6%CVE-2023-31011MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploitEPSS 0.6%CVE-2021-25684HIGHapport can be stalled by reading a FIFOEPSS 0.6%CVE-2024-20464HIGHA vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attackerEPSS 0.6%CVE-2026-3294HIGHAuthentication Logic Vulnerability on Multiple TP-Link Range ExtendersEPSS 0.6%CVE-2023-49252HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change withouEPSS 0.6%CVE-2026-29905MEDIUMKirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformedEPSS 0.6%CVE-2023-29457MEDIUMInsufficient validation of Action form input fieldsEPSS 0.6%CVE-2023-49095HIGHnexkey allows arbitrary users to impersonate any remote user due to missing signature validationEPSS 0.6%CVE-2014-5398—Schneider Electric Wonderware Input ValidationEPSS 0.6%CVE-2024-2199MEDIUM389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.cEPSS 0.6%CVE-2026-54133CRITICALjmespath.php has CompilerRuntime code injection via unescaped function namesEPSS 0.6%CVE-2024-40721HIGHCHANGING Information Technology TCBServiSign Windows Version - Improper Input ValidationEPSS 0.6%CVE-2025-66918HIGHedoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.EPSS 0.6%CVE-2026-19826MEDIUMalldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserializationEPSS 0.6%CVE-2026-75987MEDIUMSPLWare esProc SocketData.java ObjectInputStream.readUnshared deserializationEPSS 0.6%