Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2022-28126MEDIUMImproper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to poEPSS 0.2%CVE-2024-29074MEDIUMTelephony has an improper input validation vulnerabilityEPSS 0.2%CVE-2024-22382HIGHImproper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged usEPSS 0.2%CVE-2022-20507HIGHIn onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds cEPSS 0.2%CVE-2026-11034MEDIUMInsufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker toEPSS 0.2%CVE-2025-33043MEDIUMSMM buffer IntegrityEPSS 0.2%CVE-2024-28947HIGHImproper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow aEPSS 0.2%CVE-2024-13943HIGHTesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape VulnerabilityEPSS 0.2%CVE-2026-45328CRITICALESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service WrappersEPSS 0.2%CVE-2025-31488MEDIUMPlain Craft Launcher's custom homepage can use Internet Explorer to load web pages with the help of controls such as WebBrowserEPSS 0.2%CVE-2026-0416MEDIUMImproper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionalityEPSS 0.2%CVE-2022-42269HIGHNVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged lEPSS 0.2%CVE-2024-52880HIGHAn issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before versioEPSS 0.2%CVE-2026-12453MEDIUMInsufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2026-82738MEDIUMAsh.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of serviceEPSS 0.2%CVE-2026-65979MEDIUMOpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN)EPSS 0.2%CVE-2026-12034HIGHInsufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacEPSS 0.2%CVE-2026-82740LOWAsh.Type ignores outer array constraints on nested {:array, {:array, type}} inputsEPSS 0.2%CVE-2022-34443HIGH Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attaEPSS 0.2%CVE-2025-58114MEDIUMPotential XSS in Extension:CognitiveProcessDesignerEPSS 0.2%