Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-75633MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.2%CVE-2021-26327—Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.EPSS 0.2%CVE-2022-32489HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%CVE-2026-16316LOWMalformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuardEPSS 0.2%CVE-2026-79260MEDIUMImproper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2024-54011MEDIUMMissing Error/Exception HandlingEPSS 0.2%CVE-2026-62659MEDIUMAuthenticated users can make unauthorized changes on NETGEAR WAX333 Access PointsEPSS 0.2%CVE-2023-48368MEDIUMImproper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of servicEPSS 0.2%CVE-2024-9875HIGHOkta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo commEPSS 0.2%CVE-2026-17747MEDIUMInsufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had EPSS 0.2%CVE-2026-15316HIGHDenial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200EPSS 0.2%CVE-2026-7360LOWInsufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had comproEPSS 0.2%CVE-2026-8536LOWInsufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had EPSS 0.2%CVE-2025-31259HIGHA privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS EPSS 0.2%CVE-2026-87472MEDIUMImproper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2024-31965MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.2%CVE-2025-66614HIGHApache Tomcat: Client certificate verification bypass due to virtual host mappingEPSS 0.2%CVE-2024-34118MEDIUMAdobe illustrator 2024 TIF File parsing Division by zero denial of serviceEPSS 0.2%CVE-2026-79253MEDIUMImproper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social enginEPSS 0.2%CVE-2022-24418HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%