Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-78147MEDIUMggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserializationEPSS 0.6%CVE-2020-3314MEDIUMCisco AMP for Endpoints Mac Connector Software File Scan Denial of Service VulnerabilityEPSS 0.6%CVE-2024-40721HIGHCHANGING Information Technology TCBServiSign Windows Version - Improper Input ValidationEPSS 0.6%CVE-2025-61611HIGHIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privilegeEPSS 0.6%CVE-2025-1217MEDIUMHeader parser of http stream wrapper does not handle folded headersEPSS 0.6%CVE-2026-62647CRITICALA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevantEPSS 0.6%CVE-2023-36888MEDIUMMicrosoft Edge for Android (Chromium-based) Tampering VulnerabilityEPSS 0.6%CVE-2026-34685LOWAdobe Commerce | Improper Input Validation (CWE-20)EPSS 0.6%CVE-2024-22768HIGHHitron Systems DVR HVR-4781 Improper Input Validation Vulnerability EPSS 0.6%CVE-2026-40068HIGHClaude Code arbitrary code execution via git worktree commondir trust dialog bypassEPSS 0.6%CVE-2025-49554HIGHAdobe Commerce | Improper Input Validation (CWE-20)EPSS 0.6%CVE-2026-29046CRITICALTinyWeb: HTTP Header Control Character Injection into CGI EnvironmentEPSS 0.6%CVE-2026-46584LOWApache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parametersEPSS 0.6%CVE-2026-67234LOWRabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism preferenceEPSS 0.6%CVE-2024-0955MEDIUMStored XSS vulnerabilityEPSS 0.6%CVE-2024-25973MEDIUMMultiple Stored Cross-Site Scripting VulnerabilitiesEPSS 0.6%CVE-2026-28797HIGHRAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" ComponentEPSS 0.6%CVE-2024-39948HIGHA vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, cEPSS 0.6%CVE-2024-39944HIGHA vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, caEPSS 0.6%CVE-2024-39949HIGHA vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, cEPSS 0.6%