Weaknesses of type CWE-20

5,450 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-97182MEDIUMhalo-dev Halo SpEL ReplyNotificationSubscriptionHelper.java neutralizationEPSS 0.4%CVE-2026-43678MEDIUMAn unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent afEPSS 0.4%CVE-2026-22047HIGHiccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cppEPSS 0.4%CVE-2023-48425CRITICALU-Boot vulnerability resulting in persistent Code Execution EPSS 0.4%CVE-2026-14087HIGHHeap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer EPSS 0.4%CVE-2018-0122—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenEPSS 0.4%CVE-2026-45642LOWMicrosoft Azure Attestation service and Device Health Attestation Service Spoofing VulnerabilityEPSS 0.4%CVE-2025-31135MEDIUMGo-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple timesEPSS 0.4%CVE-2026-58683HIGHIn IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code executiEPSS 0.4%CVE-2026-56974HIGHIn Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remEPSS 0.4%CVE-2023-46047HIGHAn issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: EPSS 0.4%CVE-2023-24304HIGHImproper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF fileEPSS 0.4%CVE-2025-13805MEDIUMnutzam NutzBoot LiteRpc-Serializer HttpServletRpcEndpoint.java getInputStream deserializationEPSS 0.4%CVE-2025-66974HIGHAn issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a DenialEPSS 0.4%CVE-2026-54911MEDIUMUltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()EPSS 0.4%CVE-2024-33996MEDIUMmoodle: broken access control when setting calendar event typeEPSS 0.4%CVE-2024-7023HIGHInsufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation viaEPSS 0.4%CVE-2023-4552MEDIUMJava Database Connectivity (JDBC) URL ManipulationEPSS 0.4%CVE-2025-1514HIGHActive Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter CallEPSS 0.4%CVE-2026-31251HIGHCosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in EPSS 0.4%