Weaknesses of type CWE-20

5,450 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-43375HIGHThe issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.EPSS 0.3%CVE-2025-59940MEDIUMmkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholdersEPSS 0.3%CVE-2026-100177MEDIUMAil Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Cookiejar AttachmentEPSS 0.3%CVE-2024-35384MEDIUMAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.EPSS 0.3%CVE-2024-2536MEDIUMRank Math SEO with AI SEO Tools <= 1.0.214 - Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributesEPSS 0.3%CVE-2025-56404HIGHAn issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks uEPSS 0.3%CVE-2021-1432HIGHCisco IOS XE SD-WAN Software Arbitrary Command Execution VulnerabilityEPSS 0.3%CVE-2026-2695MEDIUMLack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)EPSS 0.3%CVE-2024-6541MEDIUMInformation Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 ProductsEPSS 0.3%CVE-2014-2346—COPA-DATA zenon DNP3 Improper Input ValidationEPSS 0.3%CVE-2020-16237LOWPhilips SureSigns VS4 Improper Input ValidationEPSS 0.3%CVE-2026-91738CRITICALImproper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code oEPSS 0.3%CVE-2023-38654HIGHImproper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticatedEPSS 0.3%CVE-2026-46341MEDIUMApify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix MatchingEPSS 0.3%CVE-2024-0126HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A EPSS 0.3%CVE-2022-4332MEDIUMSprecher: Vulnerable firmware verificationEPSS 0.3%CVE-2022-46701HIGHThe issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. ConnectEPSS 0.3%CVE-2026-94091MEDIUMpiskvorky gensim Model Loader utils.py load deserializationEPSS 0.3%CVE-2026-59650CRITICALMTI/A0 DH agreement exponentiates unvalidated peer valueEPSS 0.3%CVE-2020-3435MEDIUMCisco AnyConnect Secure Mobility Client for Windows Profile Modification VulnerabilityEPSS 0.3%