Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-46836MEDIUMnet-tools Stack-based Buffer Overflow vulnerabilityEPSS 0.2%CVE-2022-48189MEDIUMAn SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privEPSS 0.2%CVE-2026-11213CRITICALInsufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromEPSS 0.2%CVE-2026-13812MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who coEPSS 0.2%CVE-2025-12284MEDIUMLack of Input ValidationEPSS 0.2%CVE-2022-23403MEDIUMImproper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2025-11226HIGHConditional processing of logback.xml configuration file, in conjuction with Spring Framework and JaninoEPSS 0.2%CVE-2025-31966LOWBoolean-Based SQL Injection in Multiple Unica ComponentsEPSS 0.2%CVE-2025-11676HIGHUPnP DOS in TL-WR940N V6EPSS 0.2%CVE-2026-7989MEDIUMInsufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendeEPSS 0.2%CVE-2026-28421MEDIUMVim has a heap-buffer-overflow and a segmentation faultEPSS 0.2%CVE-2022-30542HIGHImproper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System EPSS 0.2%CVE-2023-38719MEDIUMIBM Db2 denial of serviceEPSS 0.2%CVE-2025-12001CRITICALIncorrect Content-Type HeaderEPSS 0.2%CVE-2026-19655HIGHOn affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthentEPSS 0.2%CVE-2026-11237HIGHInsufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2026-100699MEDIUMNodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 CommentEPSS 0.2%CVE-2024-33657HIGHSmm Callout in SmmComputrace ModuleEPSS 0.2%CVE-2026-60650HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2023-22342HIGHImproper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to poteEPSS 0.2%