Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2024-25116MEDIUMSpecially crafted CF.RESERVE command can lead to denial-of-serviceEPSS 0.2%CVE-2025-5148MEDIUMFunAudioLLM InspireMusic Pickle Data model.py load_state_dict deserializationEPSS 0.2%CVE-2026-56732MEDIUMZammad: Malicious input in Ticket Body Enables Session TerminationEPSS 0.2%CVE-2025-43482MEDIUMThe issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. EPSS 0.2%CVE-2026-40317CRITICALNovumOS has Privilege Escalation in the Syscall InterfaceEPSS 0.2%CVE-2026-91819MEDIUMMISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponentEPSS 0.2%CVE-2025-4742MEDIUMXU-YIJIE grpo-flat grpo_vanilla.py main deserializationEPSS 0.2%CVE-2025-4701MEDIUMVITA-MLLM Freeze-Omni utils.py torch.load deserializationEPSS 0.2%CVE-2022-45469LOWImproper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via lEPSS 0.2%CVE-2026-25684MEDIUMFile Type Control rule bypassEPSS 0.2%CVE-2025-4740MEDIUMBeamCtrl Airiana coef deserializationEPSS 0.2%CVE-2024-0080LOW NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specEPSS 0.2%CVE-2024-22390MEDIUMImproper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.EPSS 0.2%CVE-2026-84947LOWundici vulnerable to response truncation via oversized chunked responses in the dump interceptorEPSS 0.2%CVE-2022-32577LOWImproper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enablEPSS 0.2%CVE-2026-24347MEDIUMArbitrary file write to /tmp directory in EZCast Pro II DongleEPSS 0.2%CVE-2023-22662MEDIUMImproper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user tEPSS 0.2%CVE-2026-45055HIGHCubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host HeaderEPSS 0.2%CVE-2026-9982HIGHInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2022-23403MEDIUMImproper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enaEPSS 0.2%