Weaknesses of type CWE-20

5,439 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2021-0267HIGHJunos OS: Receipt of a crafted DHCP packet will cause the jdhcpd DHCP service to core.EPSS 0.5%CVE-2026-26143HIGHMicrosoft PowerShell Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2025-1088LOWVery long unicode dashboard title or panel name can hang the frontendEPSS 0.5%CVE-2022-38985HIGHThe facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidenEPSS 0.5%CVE-2024-25656MEDIUMImproper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer PremisEPSS 0.5%CVE-2023-23409MEDIUMClient Server Run-Time Subsystem (CSRSS) Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-76711HIGHUnauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.5%CVE-2023-32463LOW Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A remote unauthenticateEPSS 0.5%CVE-2022-41891MEDIUMSegfault in `tf.raw_ops.TensorListConcat` in TensorflowEPSS 0.5%CVE-2025-5878MEDIUMESAPI esapi-java-legacy SQL Injection Defense Encoder.encodeForSQL special elementEPSS 0.5%CVE-2025-6547CRITICALOn Node.js < 3, pbkdf2 silently disregards Uint8Array input, returning static keysEPSS 0.5%CVE-2025-1022HIGHVersions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by BrowEPSS 0.5%CVE-2026-76035CRITICALInappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary codeEPSS 0.5%CVE-2026-78900CRITICALImproper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code oEPSS 0.5%CVE-2026-57130HIGHPraisonAI: IMAP Command Injection via Unsanitized Email Search ParametersEPSS 0.5%CVE-2025-34157CRITICALCoolify Stored Cross-Site Scripting (XSS) in Project Name FieldEPSS 0.5%CVE-2026-79111CRITICALImproper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code ouEPSS 0.5%CVE-2026-85047CRITICALImproper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentiallEPSS 0.5%CVE-2024-30110LOWLack of input validation vulnerability affects DRYiCE AEX v10EPSS 0.5%CVE-2026-24404HIGHiccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()EPSS 0.5%