Weaknesses of type CWE-20

5,453 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-34959MEDIUMAdminer before 5.5.0 Open Redirect via X-Forwarded-PrefixEPSS 0.3%CVE-2024-9407MEDIUMBuildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instructionEPSS 0.3%CVE-2026-16641CRITICALCommerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084EPSS 0.3%CVE-2024-45301MEDIUMZDI-CAN-24744: Mintty Path Conversion Improper Input Validation Information Disclosure VulnerabilityEPSS 0.3%CVE-2021-3599MEDIUMA potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local EPSS 0.3%CVE-2026-85528MEDIUMSnowflake JDBC Driver auto-configuration account validation permits credential redirectionEPSS 0.3%CVE-2024-25008MEDIUMEricsson RAN Compute and Site Controller 6610 - Improper Input Validation VulnerabilityEPSS 0.3%CVE-2026-59322MEDIUMEmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeadersEPSS 0.3%CVE-2026-0419MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150EPSS 0.3%CVE-2026-23840CRITICALMovary vulnerable to Cross-site Scripting with `?categoryDeleted=` paramEPSS 0.3%CVE-2025-24501MEDIUMAn improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.EPSS 0.3%CVE-2025-12842MEDIUMBooking Plugin for WordPress Appointments – Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email SendingEPSS 0.3%CVE-2026-14122HIGHInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker toEPSS 0.3%CVE-2026-3096MEDIUMReverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential TheftEPSS 0.3%CVE-2024-5439MEDIUMBlocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-15246MEDIUMaizuda snail-job API FurySerializer.deserialize deserializationEPSS 0.3%CVE-2021-38122MEDIUMCross-Site Scripting (XSS) in Advance AuthenticationEPSS 0.3%CVE-2026-92581MEDIUMAVideo through 29.0 Like Counter Desynchronization via Array ParameterEPSS 0.3%CVE-2026-33284LOWGlobalLeaks has insufficient URL validation in user support APIEPSS 0.3%CVE-2026-17791MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisedEPSS 0.3%