Weaknesses of type CWE-20

5,443 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2020-10028HIGHMultiple Syscalls In GPIO Subsystem Performs No Argument ValidationEPSS 0.4%CVE-2026-20240HIGHDenial of Service through coldToFrozen.sh Script in Splunk EnterpriseEPSS 0.4%CVE-2025-32079MEDIUMSaving the right content to MediaWiki:GrowthMentors.json can take down the siteEPSS 0.4%CVE-2026-4538MEDIUMPyTorch pt2 Loading deserializationEPSS 0.4%CVE-2024-13691MEDIUMUncode <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMediaEPSS 0.4%CVE-2025-58716HIGHWindows Speech Runtime Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-47982HIGHWindows Storage VSP Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-22598HIGHManageIQ vulnerable to DoS Attack when creating TimeProfilesEPSS 0.4%CVE-2026-86879MEDIUMA denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. A remote attacker may bEPSS 0.4%CVE-2022-27574MEDIUMImproper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 ReleasEPSS 0.4%CVE-2026-76980HIGHData Exposure vulnerabilityEPSS 0.4%CVE-2026-31805MEDIUMDiscourse has a poll authorization bypass via post_id array parameterEPSS 0.4%CVE-2026-5884HIGHInsufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised thEPSS 0.4%CVE-2018-0373—A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for WindowEPSS 0.4%CVE-2023-23419HIGHWindows Resilient File System (ReFS) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-17681CRITICALInsufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attackeEPSS 0.4%CVE-2023-6073MEDIUMDoS and Control of Volume Settings for VW ID.3 ICAS3 IVI ECUEPSS 0.4%CVE-2026-13699MEDIUMDatabroker 0.6.1 PublishValue missing data_point panicEPSS 0.4%CVE-2026-34525MEDIUMAIOHTTP: Duplicate Host header acceptedEPSS 0.4%CVE-2025-9467MEDIUMPossibility to bypass file upload validation on the server-sideEPSS 0.4%