Weaknesses of type CWE-20

5,442 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-29150MEDIUMBlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.EPSS 0.4%CVE-2019-1726MEDIUMCisco NX-OS Software CLI Bypass to Internal Service VulnerabilityEPSS 0.4%CVE-2026-21061MEDIUMImproper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User inEPSS 0.4%CVE-2026-27818HIGHTerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlistEPSS 0.4%CVE-2026-52877HIGHStreambert : Insecure Protocol Execution in open-external IPC HandlerEPSS 0.4%CVE-2021-29913MEDIUMIBM Security Verify Privilege improper input validationEPSS 0.4%CVE-2025-59161LOWIn Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is leftEPSS 0.4%CVE-2026-48569HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2023-32820HIGHIn wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with noEPSS 0.4%CVE-2026-27607HIGHRustFS's Missing Post Policy Validation leads to Arbitrary Object WriteEPSS 0.4%CVE-2024-1471MEDIUMHTML Injection VulnerabilityEPSS 0.4%CVE-2025-3590MEDIUMAdianti Framework deserializationEPSS 0.4%CVE-2026-13603CRITICALSSRF with API key leak in pretix-oppwaEPSS 0.4%CVE-2026-95674MEDIUMMISP EventsController queryEnrichment allows querying unavailable or legacy modules without validationEPSS 0.4%CVE-2026-47662HIGHPathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLsEPSS 0.4%CVE-2025-59895HIGHRemote denial-of-service (DoS) vulnerability in Sync Breeze Enterprise ServerEPSS 0.4%CVE-2023-0896HIGHA default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attackEPSS 0.4%CVE-2023-2267MEDIUMImproper input validation could lead to reflection injection attacksEPSS 0.4%CVE-2021-1367MEDIUMCisco NX-OS Software Protocol Independent Multicast Denial of Service VulnerabilityEPSS 0.4%CVE-2025-50490HIGHImproper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attacEPSS 0.4%