Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-44779MEDIUMAn issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.EPSS 0.2%CVE-2026-13006HIGHIncomplete protection against CVE-2025-11226EPSS 0.2%CVE-2022-37327MEDIUMImproper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 EPSS 0.2%CVE-2024-3173HIGHInsufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escaEPSS 0.2%CVE-2025-27493CRITICALA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < VEPSS 0.2%CVE-2023-24571HIGH Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with administrator privileges could potEPSS 0.2%CVE-2025-66225HIGHOrangeHRM is Vulnerable to Account Takeover Through Unvalidated Username in Password Reset WorkflowEPSS 0.2%CVE-2024-36482HIGHImproper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2022-32490HIGH Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabilEPSS 0.2%CVE-2024-27240HIGHZoom Apps for Windows - Improper Input ValidationEPSS 0.2%CVE-2022-32144HIGHThere is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to serviEPSS 0.2%CVE-2023-25522HIGH NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by providing configuratiEPSS 0.2%CVE-2023-32633MEDIUMImproper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially eEPSS 0.2%CVE-2026-60640HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-76816LOWNetty: MQTT Topic Name and Client ID Validation BypassEPSS 0.2%CVE-2026-10942HIGHInappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform privilege escalatiEPSS 0.2%CVE-2022-20590MEDIUMIn valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lEPSS 0.2%CVE-2023-25772MEDIUMImproper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may allow an authenticateEPSS 0.2%CVE-2022-20592MEDIUMIn ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local iEPSS 0.2%CVE-2026-28852MEDIUMA stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4EPSS 0.2%