Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2023-42766HIGHImproper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of EPSS 0.2%CVE-2025-24308HIGHImproper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentEPSS 0.2%CVE-2025-20034MEDIUMImproper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards before vEPSS 0.2%CVE-2025-20009MEDIUMImproper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards may allow a privilegeEPSS 0.2%CVE-2023-38587HIGHImproper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via locaEPSS 0.2%CVE-2023-29495HIGHImproper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2025-11143LOWThe Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs EPSS 0.2%CVE-2023-28743HIGHImproper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2022-27826HIGHImproper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.2%CVE-2026-86924MEDIUMA memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 2EPSS 0.2%CVE-2024-33659MEDIUMBiosGuard Buffer Overflow and TOCTOU VulnerabilityEPSS 0.2%CVE-2026-54577LOWmport audit can inspect the wrong package when options are presentEPSS 0.2%CVE-2026-5941HIGHFoxit PDF Editor/Reader AcroForm Signature Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-47470MEDIUMNVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by EPSS 0.2%CVE-2023-31339MEDIUMImproper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform EPSS 0.2%CVE-2024-8518LOWCWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted proEPSS 0.2%CVE-2026-50144HIGHncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negative parameter idEPSS 0.2%CVE-2026-23566MEDIUMLog Injection in Content Distribution Service UDP HandlerEPSS 0.2%CVE-2026-24345MEDIUMCross-Site Request Forgery in EZCast Pro II DongleEPSS 0.2%CVE-2026-11273MEDIUMInsufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a userEPSS 0.2%