Weaknesses of type CWE-20

5,432 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2018-15431—Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution VulnerabilitiesEPSS 0.5%CVE-2023-22963MEDIUMThe personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-9]$ regular expressiEPSS 0.5%CVE-2026-49830MEDIUMDSpace: ORE resource URI does not validate scheme for non-web resourcesEPSS 0.5%CVE-2022-24926MEDIUMImproper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victimEPSS 0.5%CVE-2026-48188CRITICALSQL Injection via MySQL Quote MethodEPSS 0.5%CVE-2026-13794HIGHInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker whEPSS 0.5%CVE-2025-5326MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 verifyToken deserializationEPSS 0.5%CVE-2026-62295HIGHHAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2024-37917HIGHPexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a EPSS 0.5%CVE-2026-62296HIGHHAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2026-38891HIGHAn improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cause a Denial of ServiEPSS 0.5%CVE-2026-42566HIGHMeshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failureEPSS 0.5%CVE-2026-36501HIGHAn issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.5%CVE-2022-31172HIGHOpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signersEPSS 0.5%CVE-2025-60012MEDIUMApache Livy: Restrict file accessEPSS 0.5%CVE-2026-61634NONERabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_maxEPSS 0.5%CVE-2026-40454HIGHApache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server dataEPSS 0.5%CVE-2024-7005HIGHInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.5%CVE-2026-26452HIGHccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when pEPSS 0.5%CVE-2025-8963MEDIUMjeecgboot JimuReport Data Large Screen Template testConnection deserializationEPSS 0.5%