Weaknesses of type CWE-20

5,450 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-5455HIGHPossible denial of service when passing malformed data in a URL to qDecodeDataUrlEPSS 0.4%CVE-2026-3912HIGHTIBCO ActiveMatrix BusinessWorks Injection VulnerabilityEPSS 0.4%CVE-2026-4982HIGHUnauthorized access to chat contentsEPSS 0.4%CVE-2023-38057MEDIUMXSS stored in survey answersEPSS 0.4%CVE-2023-4553MEDIUMUnauthenticated Access to AppBuilder Configuration FilesEPSS 0.4%CVE-2025-54785HIGHSuiteCRM is Vulnerable to PHP Object Injection in ReportsEPSS 0.4%CVE-2025-2305HIGHLocal file inclusion vulnerability in LIVE CONTRACTEPSS 0.4%CVE-2026-30576HIGHA Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application faEPSS 0.4%CVE-2024-37406HIGHIn Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domEPSS 0.4%CVE-2026-13602HIGHSession takeover vulnerabilityEPSS 0.4%CVE-2026-54728MEDIUMbunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWebEPSS 0.4%CVE-2015-6563MEDIUMThe monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX reEPSS 0.4%CVE-2026-33369MEDIUMZimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operatioEPSS 0.4%CVE-2026-25126HIGHPolarLearn's unvalidated vote direction allows vote count manipulationEPSS 0.4%CVE-2023-3434MEDIUMQRC Handler without Input Validation in JamiEPSS 0.4%CVE-2025-3622MEDIUMXorbits Inference model.py load deserializationEPSS 0.4%CVE-2026-53541MEDIUMOliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input FilteringEPSS 0.4%CVE-2024-20334MEDIUMA vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attaEPSS 0.4%CVE-2026-67969HIGHAn issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a craftEPSS 0.4%CVE-2026-46669HIGH`openvm-pairing` pairing check missing proper subfield check on scaling factorEPSS 0.4%