Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-1736MEDIUMStream HTTP wrapper header check might omit basic auth headerEPSS 0.5%CVE-2020-15731LOWLocal Privilege Escalation in Bitdefender Engines (VA-8953)EPSS 0.5%CVE-2020-3409HIGHCisco IOS and IOS XE Software PROFINET Denial of Service VulnerabilityEPSS 0.5%CVE-2025-5114MEDIUMeasysoft zentaopms Editor index.php edit deserializationEPSS 0.5%CVE-2026-44978MEDIUMxrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verificationEPSS 0.5%CVE-2026-51997HIGHAn issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functionsEPSS 0.5%CVE-2021-25489LOWAssuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format stEPSS 0.5%KEVCVE-2026-82008CRITICALAdobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2026-22102CRITICALArbitrary file overwrite through certificate update functionalityEPSS 0.5%CVE-2020-1633HIGHJunos OS: MX Series: Crafted packets traversing a Broadband Network Gateway (BNG) configured with IPv6 NDP proxy could lead to Denial of ServiceEPSS 0.5%CVE-2020-17393MEDIUMThis vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker mEPSS 0.5%CVE-2025-10769MEDIUMh2oai h2o-3 H2 JDBC Driver ImportSQLTable deserializationEPSS 0.5%CVE-2026-2750CRITICALCommand Injection via CLAPI generatetrapsEPSS 0.5%CVE-2026-53412CRITICALZoom Workplace VDI Plugin for Windows - Improper Input ValidationEPSS 0.5%CVE-2022-34159HIGHHuawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device service exceptions.EPSS 0.5%CVE-2026-35081HIGHArbitrary process termination vulnerability in method ugw-logstopEPSS 0.5%CVE-2025-20146HIGHCisco IOS XR Software for ASR 9000 Series Routers Layer 3 Multicast Routing Denial of Service VulnerabilityEPSS 0.5%CVE-2026-32735LOWUnpacking Arbitrary Mustache Template Files via `maven-dependency-plugin`EPSS 0.5%CVE-2026-54254MEDIUMCyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sitesEPSS 0.5%CVE-2018-14656HIGHA missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel memory at an arbitrarEPSS 0.5%