Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-16421HIGHInappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code insideEPSS 0.5%CVE-2022-39016HIGHJavascript injection in PDFtron in M-Files HubshareEPSS 0.5%CVE-2024-21627HIGHSome attribute not escaped in Validate::isCleanHTML methodEPSS 0.5%CVE-2026-33936MEDIUMpython-ecdsa: Denial of Service via improper DER length validation in crafted private keysEPSS 0.5%CVE-2026-54405HIGHA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to EPSS 0.5%CVE-2026-16632MEDIUMboazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validationEPSS 0.5%CVE-2026-22547CRITICALGitea repository creation accepts invalid field valuesEPSS 0.5%CVE-2026-3641MEDIUMAppmax <= 1.0.3 - Missing Authorization to Order Status Manipulation and Arbitrary Order Creation via Webhook EndpointEPSS 0.5%CVE-2026-67296HIGHFreeRDP before 3.29.0 Denial of Service via RDPEI PDUEPSS 0.5%CVE-2023-21515HIGHInstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to exEPSS 0.5%CVE-2026-27959HIGHKoa has Host Header Injection via `ctx.hostname`EPSS 0.5%CVE-2026-24512HIGHingress-nginx auth-method nginx configuration injectionEPSS 0.5%CVE-2023-21514HIGHImproper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API toEPSS 0.5%CVE-2022-39012HIGHHuawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application servEPSS 0.5%CVE-2026-54208HIGHTeamDavid: Arbitrary File Write leading to Stored XSSEPSS 0.5%CVE-2023-6835MEDIUMMultiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating couldEPSS 0.5%CVE-2023-35306MEDIUMMicrosoft PostScript and PCL6 Class Printer Driver Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-71399HIGHBetter Auth before 1.4.5 Path Normalization Bypass via rou3EPSS 0.5%CVE-2023-39191HIGHKernel: ebpf: insufficient stack type checks in dynptrEPSS 0.5%CVE-2021-28547HIGHAdobe Creative Cloud for macOS Privilege Escalation VulnerabilityEPSS 0.5%