Weaknesses of type CWE-20

5,430 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2020-3489HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service VulnerabilitiesEPSS 0.5%CVE-2026-34445HIGHONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.EPSS 0.5%CVE-2024-22117LOWValue of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is addedEPSS 0.5%CVE-2024-43115HIGHApache DolphinScheduler: Alert Script AttackEPSS 0.5%CVE-2025-9287CRITICALMissing type checks leading to hash rewind and passing on crafted dataEPSS 0.5%CVE-2018-0235—A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjaEPSS 0.5%CVE-2026-1580HIGHingress-nginx auth-method nginx configuration injectionEPSS 0.5%CVE-2021-33110MEDIUMImproper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windows 10 and 11 before EPSS 0.5%CVE-2026-45783HIGHlibp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodesEPSS 0.5%CVE-2026-50370HIGHDHCP Server Service Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-49774HIGHModuleScanner flaws in SuiteCRMEPSS 0.5%CVE-2025-31995LOWHCL Unica MaxAI Workbench is vulnerable to improper input validationEPSS 0.5%CVE-2025-59190MEDIUMWindows Search Service Denial of Service VulnerabilityEPSS 0.5%CVE-2026-29909MEDIUMMRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpointEPSS 0.5%CVE-2026-4755CRITICALCWE-20 in MolotovCherry Android-ImageMagick7EPSS 0.5%CVE-2024-7507HIGHRockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix® 5380 Controller Denial-of-Service Vulnerability via Input ValidationEPSS 0.5%CVE-2018-14799—In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize datEPSS 0.5%CVE-2026-40712CRITICALDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high prEPSS 0.5%CVE-2026-46738CRITICALDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high prEPSS 0.5%CVE-2026-40714HIGHDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attackeEPSS 0.5%