Weaknesses of type CWE-20

5,441 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-3967MEDIUMAlfresco Activiti Process Variable Serialization System SerializableType.java createObjectInputStream deserializationEPSS 0.4%CVE-2026-27906MEDIUMWindows Hello Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2022-23425HIGHImproper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with EPSS 0.4%CVE-2026-90490MEDIUMlenve vhr MailReceiver deserializationEPSS 0.4%CVE-2026-55072HIGHPimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table nameEPSS 0.4%CVE-2026-8735MEDIUMOinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserializationEPSS 0.4%CVE-2026-3470LOWA vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowiEPSS 0.4%CVE-2023-24062MEDIUMDiebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory strucEPSS 0.4%CVE-2026-9497MEDIUMchangmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserializationEPSS 0.4%CVE-2026-7712MEDIUMMindsDB Pickle pickle.loads deserializationEPSS 0.4%CVE-2026-83492MEDIUMWordPress Kubio AI Website Builder - Denial Of ServiceEPSS 0.4%CVE-2026-12787MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserializationEPSS 0.4%CVE-2025-1741MEDIUMb1gMail Admin Page users.php deserializationEPSS 0.4%CVE-2024-48918HIGHLack of Input Validation in RDS Light - Potential for Injection Attacks and Memory TamperingEPSS 0.4%CVE-2026-27585MEDIUMCaddy's improper sanitization of glob characters in file matcher may lead to bypassing security protectionsEPSS 0.4%CVE-2023-2808MEDIUMLack of URL normalization allows rendering previews for disallowed domainsEPSS 0.4%CVE-2026-20254MEDIUMInformation Disclosure through External Content Restriction Bypass in Splunk EnterpriseEPSS 0.4%CVE-2023-0869MEDIUMCross-site scripting in outage/list.htmEPSS 0.4%CVE-2023-42508MEDIUMJFrog Artifactory Improper header input validation leads to email manipulation sent from the platformEPSS 0.4%CVE-2024-25999HIGHPHOENIX CONTACT: Privilege escalation in the OCPP agent serviceEPSS 0.4%