Weaknesses of type CWE-20

5,429 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2023-44192HIGHJunos OS: QFX5000 Series: DMA memory leak is observed when specific DHCP packets are transmitted over pseudo-VTEPEPSS 0.5%CVE-2024-36737HIGHImproper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value EPSS 0.5%CVE-2021-0173MEDIUMImproper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some KEPSS 0.5%CVE-2024-36734HIGHImproper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value EPSS 0.5%CVE-2021-0174MEDIUMImproper Use of Validation Framework in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) WEPSS 0.5%CVE-2023-44185HIGHJunos OS and Junos OS Evolved: In an BGP scenario RPD crashes upon receiving and processing a specific malformed ISO VPN BGP UPDATE packetEPSS 0.5%CVE-2024-22054HIGHA malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device maEPSS 0.5%CVE-2026-45678HIGHOpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloadsEPSS 0.5%CVE-2021-0175MEDIUMImproper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operatiEPSS 0.5%CVE-2026-63335MEDIUMRabbitMQ Java client malformed body frame triggers raw command assembler exceptionEPSS 0.5%CVE-2024-36740HIGHAn issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the rangEPSS 0.5%CVE-2021-0165MEDIUMImproper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 anEPSS 0.5%CVE-2026-33287HIGHLiquidJS has Exponential Memory Amplification through its replace_first Filter $& PatternEPSS 0.5%CVE-2021-0172MEDIUMImproper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in WinEPSS 0.5%CVE-2021-0183MEDIUMImproper Validation of Specified Index, Position, or Offset in Input in software for some Intel(R) PROSet/Wireless Wi-Fi in multiple operatiEPSS 0.5%CVE-2024-20495HIGHA vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTDEPSS 0.5%CVE-2025-20154HIGHCisco IOS, IOS XE and IOS XR Software TWAMP Denial of Service VulnerabilityEPSS 0.5%CVE-2025-5680MEDIUMShenzhen Dashi Tongzhou Information Technology AgileBPM Groovy Script SysScriptController.java executeScript deserializationEPSS 0.5%CVE-2025-5679MEDIUMShenzhen Dashi Tongzhou Information Technology AgileBPM SysToolsController.java parseStrByFreeMarker deserializationEPSS 0.5%CVE-2022-39376LOWImproper input validation on emails links in GLPIEPSS 0.5%