Weaknesses of type CWE-20

5,444 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-13699MEDIUMDatabroker 0.6.1 PublishValue missing data_point panicEPSS 0.4%CVE-2024-4027HIGHUndertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacksEPSS 0.4%CVE-2026-17664MEDIUMInsufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised tEPSS 0.4%CVE-2022-47909MEDIUMLQL Injection in Livestatus HTTP headersEPSS 0.4%CVE-2026-45628CRITICALDokploy: Command Injection via Unescaped Branch Fields in Deployment PipelineEPSS 0.4%CVE-2026-48774HIGHProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contractEPSS 0.4%CVE-2026-79410HIGHImproper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce theiEPSS 0.4%CVE-2025-60537MEDIUMImproper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute EPSS 0.4%CVE-2026-9211MEDIUMCertain NETGEAR routers allow unauthenticated users to gain control of the routerEPSS 0.4%CVE-2025-61235CRITICALAn issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields cEPSS 0.4%CVE-2026-4519HIGHwebbrowser.open() allows leading dashes in URLsEPSS 0.4%CVE-2017-14025—An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identifiedEPSS 0.4%CVE-2025-32077MEDIUMXSSes in Extension:SimpleCalendarEPSS 0.4%CVE-2026-50569MEDIUMFission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checksEPSS 0.4%CVE-2026-52780CRITICALOpenProject: Cache store poisoning leads to Remote Code Execution (RCE)EPSS 0.4%CVE-2026-65604HIGHSkipper Incomplete Fix for CVE-2026-50197 Policy BypassEPSS 0.4%CVE-2025-24319HIGHBIG-IP Next Central Manager vulnerabilityEPSS 0.4%CVE-2018-15368—Cisco IOS XE Software Privileged EXEC Mode Root Shell Access VulnerabilityEPSS 0.4%CVE-2025-50494HIGHImproper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackersEPSS 0.4%CVE-2026-95659MEDIUMMISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind ThreadEPSS 0.4%