Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-1026HIGHVersions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through tEPSS 0.5%CVE-2024-23669MEDIUMAn improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2EPSS 0.5%CVE-2025-34123HIGHVideoCharge Studio 2.12.3.685 SEH Buffer Overflow via .VSC FileEPSS 0.5%CVE-2024-27912HIGHA denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending EPSS 0.5%CVE-2024-32992HIGHInsufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.5%CVE-2024-56321LOWGoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host accessEPSS 0.5%CVE-2022-41921LOWDiscourse chat messages should have a maximum character limitEPSS 0.5%CVE-2021-33146MEDIUMImproper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unautEPSS 0.5%CVE-2025-55173MEDIUMNext.js Content Injection Vulnerability for Image OptimizationEPSS 0.5%CVE-2026-16520HIGHImproper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians GeniaEPSS 0.5%CVE-2025-12275CRITICALMail Configuration File Manipulation + Command ExecutionEPSS 0.5%CVE-2026-78009HIGHFireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS)EPSS 0.5%CVE-2018-4843MEDIUMA vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All EPSS 0.5%CVE-2026-54588CRITICALPoweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.EPSS 0.5%CVE-2023-31161MEDIUMImproper Input Validation in Web InterfaceEPSS 0.5%CVE-2025-2855MEDIUMelunez eladmin upload checkFile deserializationEPSS 0.5%CVE-2026-26062HIGHFleet server may terminate unexpectedly when handling certain gRPC requestsEPSS 0.5%CVE-2025-26358MEDIUMA CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an EPSS 0.5%CVE-2025-3413MEDIUMopplus springboot-admin SysGeneratorController.java code deserializationEPSS 0.5%CVE-2024-12994MEDIUMrunning-elephant Datart File Upload import extractModel deserializationEPSS 0.5%