Weaknesses of type CWE-20

5,455 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2026-21065MEDIUMOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.EPSS 0.2%CVE-2024-41167HIGHImproper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to potentially enable EPSS 0.2%CVE-2024-22338MEDIUMIBM Security Verify Access OIDC Provider information disclosureEPSS 0.2%CVE-2024-39811MEDIUMImproper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalatiEPSS 0.2%CVE-2026-43722MEDIUMThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.EPSS 0.2%CVE-2026-35369MEDIUMuutils coreutils kill System-wide Process Termination and Denial of Service via Argument MisinterpretationEPSS 0.2%CVE-2026-78237HIGHInsufficient input validation in Admin By Request (ABR)EPSS 0.2%CVE-2024-38483MEDIUMDell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local acEPSS 0.2%CVE-2026-34383MEDIUMAdmidio: CSRF and Form Validation Bypass in Inventory Item Save via `imported` ParameterEPSS 0.2%CVE-2026-43895MEDIUMjq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifactsEPSS 0.2%CVE-2026-20627MEDIUMAn issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.EPSS 0.2%CVE-2023-31366LOWImproper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of EPSS 0.1%CVE-2017-3772MEDIUMA vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.EPSS 0.1%CVE-2026-56975MEDIUMIn Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denEPSS 0.1%CVE-2025-24296MEDIUMImproper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial ofEPSS 0.1%CVE-2026-60526MEDIUMVulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. EPSS 0.1%CVE-2026-30769HIGHAn issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sEPSS 0.1%CVE-2026-11221MEDIUMInsufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromiEPSS 0.1%CVE-2026-35347MEDIUMuutils coreutils comm Silent Data Loss or Denial of Service via Improper Input ValidationEPSS 0.1%CVE-2021-37677MEDIUMMissing validation in shape inference for `Dequantize` in TensorFlowEPSS 0.1%