Weaknesses of type CWE-20

5,453 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-10968HIGHInsufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compEPSS 0.3%CVE-2026-34762LOWElla Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriberEPSS 0.3%CVE-2026-11008MEDIUMInsufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had comprEPSS 0.3%CVE-2025-71417HIGHPocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponsePacketEPSS 0.3%CVE-2025-15035MEDIUMArbitrary File Deletion Vulnerability in TP-Link Archer AXE75EPSS 0.3%CVE-2026-19509MEDIUMRDK WebUI DOS vulnerabilityEPSS 0.3%CVE-2026-18211MEDIUMKeycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domainsEPSS 0.3%CVE-2021-0072MEDIUMImproper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in WinEPSS 0.3%CVE-2025-67493HIGHHomarr: missing input sanitization and possible privilege escalation through ldap search query injectionEPSS 0.3%CVE-2026-16378HIGHOther issue in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.3%CVE-2024-52592MEDIUMMissing validation allows spoofed poll updates in MisskeyEPSS 0.3%CVE-2026-33729MEDIUMOpenFGA has an Authorization Bypass through cached keysEPSS 0.3%CVE-2026-33589HIGHArbitrary File Read via Local File Inclusion (LFI)EPSS 0.3%CVE-2023-28981MEDIUMJunos OS and Junos OS Evolved: If malformed IPv6 router advertisements are received, memory corruption will occur which causes an rpd crashEPSS 0.3%CVE-2026-44518MEDIUMliboqs: XMSS Buffer Overread BugEPSS 0.3%CVE-2025-66400MEDIUMmdast-util-to-hast unsanitized class attributeEPSS 0.3%CVE-2026-10911HIGHInsufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2025-59187HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-10917HIGHInsufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2025-1080HIGHMacro URL arbitrary script executionEPSS 0.3%