Weaknesses of type CWE-20

5,439 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-54694CRITICALNationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account TakeoverEPSS 0.5%CVE-2025-54247MEDIUMAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2021-25738MEDIUMCode exec via yaml parsingEPSS 0.5%CVE-2025-62455HIGHMicrosoft Message Queuing (MSMQ) Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-51017HIGHPocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin DataEPSS 0.5%CVE-2021-35268MEDIUMIn NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow EPSS 0.5%CVE-2022-41888MEDIUMUnckecked rank size in `tf.image.generate_bounding_box_proposals` in TensorflowEPSS 0.5%CVE-2026-56151MEDIUMImproper Input Validation in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2025-52569MEDIUMGitHub.jl lacks validation for user-provided fieldsEPSS 0.5%CVE-2026-26063HIGHCediPay Affected by Improper Input Validation in Payment ProcessingEPSS 0.5%CVE-2026-56349MEDIUMn8n - Guardrail Node Bypass via Crafted InputEPSS 0.5%CVE-2025-50233MEDIUMA vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of tEPSS 0.5%CVE-2026-9212MEDIUMInsufficient authentication and input validation in certain NETGEAR productsEPSS 0.5%CVE-2026-30077HIGHOpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistEPSS 0.5%CVE-2025-50178MEDIUMGitForge.jl lacks validation for user provided fieldsEPSS 0.5%CVE-2026-63734MEDIUMSurrealDB before 3.2.0 Denial of Service via malformed SurrealML importEPSS 0.5%CVE-2025-58175MEDIUMGeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity ResolutionEPSS 0.5%CVE-2025-21370HIGHWindows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-47931HIGHColdFusion | Improper Input Validation (CWE-20)EPSS 0.5%CVE-2024-9348HIGHDocker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build viewEPSS 0.5%