Weaknesses of type CWE-20

5,453 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-0660MEDIUMStored XSS in Folder Function by Rogue AdminEPSS 0.3%CVE-2026-17679MEDIUMInsufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comproEPSS 0.3%CVE-2026-79288MEDIUMImproper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inEPSS 0.3%CVE-2025-24847MEDIUMImproper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an inEPSS 0.3%CVE-2026-13847MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leaEPSS 0.3%CVE-2025-8571MEDIUMConcrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard PageEPSS 0.3%CVE-2026-33588HIGHArbitrary File Write Through Path TraversalEPSS 0.3%CVE-2023-7248MEDIUMOpenText Vertica Management console might be prone to bypass via crafted requestsEPSS 0.3%CVE-2022-2868—libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacEPSS 0.3%CVE-2025-10061MEDIUMMalformed $group Query May Cause MongoDB Server to CrashEPSS 0.3%CVE-2024-0045HIGHIn smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proxiEPSS 0.3%CVE-2026-20715HIGHImproper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard ManageabEPSS 0.3%CVE-2026-18206LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching bypassEPSS 0.3%CVE-2026-87590MEDIUMImproper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive inforEPSS 0.3%CVE-2026-6231MEDIUMbson_validate may skip validation when processing certain inputsEPSS 0.3%CVE-2026-14225LOWEasy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist BypassEPSS 0.3%CVE-2022-29211MEDIUMSegfault in TensorFlow if `tf.histogram_fixed_width` is called with NaN valuesEPSS 0.3%CVE-2026-79013MEDIUMImproper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafEPSS 0.3%CVE-2023-22239HIGHAdobe After Effects Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-13889MEDIUMSide-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak crossEPSS 0.3%