Weaknesses of type CWE-20

5,454 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-34669MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.3%CVE-2022-26862MEDIUMPrior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vuEPSS 0.3%CVE-2022-26864MEDIUMPrior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vuEPSS 0.3%CVE-2021-0176MEDIUMImproper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in WinEPSS 0.3%CVE-2026-1782MEDIUMMetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'EPSS 0.3%CVE-2025-63785MEDIUMA DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerabilEPSS 0.3%CVE-2022-21136MEDIUMImproper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via localEPSS 0.3%CVE-2024-21976HIGHImproper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary cEPSS 0.3%CVE-2026-101266LOWCheckout validation bypassEPSS 0.3%CVE-2025-67170MEDIUMA reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user'sEPSS 0.3%CVE-2022-26863MEDIUMPrior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vuEPSS 0.3%CVE-2026-11113CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2026-82441CRITICALApache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency KeysEPSS 0.3%CVE-2025-48985LOWA vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypEPSS 0.3%CVE-2021-0159HIGHImproper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enabEPSS 0.3%CVE-2026-79251MEDIUMImproper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin poliEPSS 0.3%CVE-2022-28190MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where imprEPSS 0.3%CVE-2021-0154HIGHImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation ofEPSS 0.3%CVE-2026-11120CRITICALInsufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who hadEPSS 0.3%CVE-2026-11242HIGHInsufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised EPSS 0.3%