Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2024-8518LOWCWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted proEPSS 0.2%CVE-2024-37027MEDIUMImproper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentiallEPSS 0.2%CVE-2026-32603HIGHSandboxie kernel driver denial of service via malformed IOCTL from sandboxed processEPSS 0.2%CVE-2023-4753LOWOpenHarmony v3.2.1 and prior version has a system call function usage errorEPSS 0.2%CVE-2023-24465MEDIUMCommunication Wi-Fi  subsystem has a null pointer reference vulnerability when receving external data.EPSS 0.2%CVE-2026-7961MEDIUMInsufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network sEPSS 0.2%CVE-2026-17870MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment EPSS 0.2%CVE-2026-17844MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment EPSS 0.2%CVE-2026-21768MEDIUMHCL Verse for Android is susceptible to an injection vulnerabilityEPSS 0.2%CVE-2026-21072MEDIUMImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2026-1858MEDIUMwget2 Improper Certificate ValidationEPSS 0.2%CVE-2026-21071MEDIUMImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memorEPSS 0.2%CVE-2026-21066MEDIUMImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2026-11286MEDIUMInsufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2024-55567HIGHImproper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62EPSS 0.2%CVE-2026-11126MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicEPSS 0.2%CVE-2025-11934LOWImproper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerifyEPSS 0.2%CVE-2021-37673MEDIUM`CHECK`-fail in `MapStage` in TensorFlowEPSS 0.2%CVE-2026-0412MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150 Web UIEPSS 0.2%CVE-2024-10083MEDIUMCWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver inEPSS 0.2%