Weaknesses of type CWE-20

5,439 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-95843HIGHMoquette malformed shared subscriptions can crash command processingEPSS 0.4%CVE-2023-22940MEDIUMSPL Command Safeguards Bypass via the ‘collect’ SPL Command Aliases in Splunk EnterpriseEPSS 0.4%CVE-2024-20274MEDIUMCisco Secure Firewall Management Center HTML Injection VulnerabilityEPSS 0.4%CVE-2026-84504HIGHfastify vulnerable to request body replacement via an async validation result collisionEPSS 0.4%CVE-2026-22072HIGHArbitrary URL Loading in WebView Leading to Token Leakage RiskEPSS 0.4%CVE-2026-53901HIGHCerebrate before v1.37 allows mass assignment of record identifiers during object creationEPSS 0.4%CVE-2025-59535MEDIUMDotNetNuke.Core allows loading of unused themes on anonymous clients through query parametersEPSS 0.4%CVE-2026-16551MEDIUMDenial-of-Service in OpenCanary's MongoDB moduleEPSS 0.4%CVE-2023-38417MEDIUMImproper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentiaEPSS 0.4%CVE-2016-2781MEDIUMchroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, whiEPSS 0.4%CVE-2026-6409HIGHDenial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted inputEPSS 0.4%CVE-2025-11936MEDIUMPotential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHelloEPSS 0.4%CVE-2024-7004MEDIUMInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.4%CVE-2026-31799MEDIUMTautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parametersEPSS 0.4%CVE-2026-32149HIGHWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-29143HIGHS/MIME Decryption ImpersonationEPSS 0.4%CVE-2023-0881HIGHDDoS in Ubuntu package linux-bluefieldEPSS 0.4%CVE-2026-22699HIGHRustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()EPSS 0.4%CVE-2017-12336—A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the intEPSS 0.4%CVE-2018-0302—A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attaEPSS 0.4%