Weaknesses of type CWE-20

5,450 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2023-4552MEDIUMJava Database Connectivity (JDBC) URL ManipulationEPSS 0.4%CVE-2023-28733HIGHStored XSS affecting the AcyMailing plugin for Joomla EPSS 0.4%CVE-2025-1514HIGHActive Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter CallEPSS 0.4%CVE-2024-3488MEDIUMFile Upload vulnerability in unauthenticated session found in iManager.EPSS 0.4%CVE-2026-31251HIGHCosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in EPSS 0.4%CVE-2026-27913HIGHWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2025-69232LOWfree5GC hasProtocol Compliance Violation in UPF Leading to SMF Service DisruptionEPSS 0.4%CVE-2025-10461MEDIUMGlobal file reads caused by improper URL checks in webserverEPSS 0.4%CVE-2022-28329—A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALAEPSS 0.4%CVE-2023-35936MEDIUMArbitrary file write is possible in Pandoc when using PDF output or --extract-media with untrusted inputEPSS 0.4%CVE-2023-47855MEDIUMImproper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enablEPSS 0.4%CVE-2022-22163HIGHJunos OS: jdhcpd crashes upon receipt of a specific DHCPv6 packetEPSS 0.4%CVE-2024-21453HIGHImproper Input Validation in Automotive TelematicsEPSS 0.4%CVE-2026-102600HIGHSocket.IO: Prototype Pollution via Unsafe Client Session LookupEPSS 0.4%CVE-2024-23717CRITICALIn access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validatiEPSS 0.4%CVE-2025-7693CRITICALRockwell Automation Micro800 VulnerabilityEPSS 0.4%CVE-2021-43548MEDIUMPhilips Patient Information Center iX (PIC iX) and Efficia CM Series Improper Input ValidationEPSS 0.4%CVE-2026-25631MEDIUMDomain allowlist bypass enables credential exfiltrationEPSS 0.4%CVE-2026-27443HIGHS/MIME Decryption Tag Sanitization BypassEPSS 0.4%CVE-2025-0958MEDIUMUltimate WordPress Auction Plugin <= 4.2.9 - Missing Authorization to Arbitrary Post DeletionEPSS 0.4%