Weaknesses of type CWE-20

5,430 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-0841MEDIUMAridius XYZ News loadMore deserializationEPSS 0.5%CVE-2023-49796MEDIUMMindsDB Arbitrary File Write vulnerabilityEPSS 0.5%CVE-2026-84469HIGHfastify vulnerable to request validation bypass via skipped boolean false schemasEPSS 0.5%CVE-2025-6444MEDIUMServiceStack GetErrorResponse Improper Input Validation NTLM Relay VulnerabilityEPSS 0.5%CVE-2024-7974HIGHInsufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruptEPSS 0.5%CVE-2026-47928CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2023-7060HIGHMissing Security Control in Zephyr OS IP Packet HandlingEPSS 0.5%CVE-2026-48284CRITICALColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2024-39950HIGHA vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities toEPSS 0.5%CVE-2026-54205MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionalityEPSS 0.5%CVE-2026-54206MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionalityEPSS 0.5%CVE-2026-54207MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionalityEPSS 0.5%CVE-2022-34436LOW Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuraEPSS 0.5%CVE-2024-27931MEDIUMInsufficient permission checking in `Deno.makeTemp*` APIsEPSS 0.5%CVE-2022-34885HIGHAn improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbEPSS 0.5%CVE-2025-59952HIGHminio-java Client XML Tag is Vulnerable to Value SubstitutionEPSS 0.5%CVE-2026-59354CRITICALSpring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadataEPSS 0.5%CVE-2023-35163MEDIUMVega's validators able to submit duplicate transactions EPSS 0.5%CVE-2021-3442—A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripEPSS 0.5%CVE-2018-15431—Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution VulnerabilitiesEPSS 0.5%