Weaknesses of type CWE-20

5,456 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-24484HIGHImproper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticEPSS 0.1%CVE-2026-81686MEDIUMopenssl_encrypt before 1.4.9 D-Bus Properties Authorization BypassEPSS 0.1%CVE-2025-24486HIGHImproper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticEPSS 0.1%CVE-2022-27829HIGHImproper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2025-7378MEDIUMAn improper input validation vulnerability was found on manipulating configuration of ADMEPSS 0.1%CVE-2022-27830HIGHImproper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.1%CVE-2025-32004LOWImproper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalatiEPSS 0.1%CVE-2025-26474LOWcommunication_ipc an improper input validation vulnerabilityEPSS 0.1%CVE-2026-12456MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2025-20096MEDIUMImproper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adveEPSS 0.1%CVE-2022-39880HIGHImproper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary EPSS 0.1%CVE-2026-84666MEDIUMJenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration thEPSS 0.1%CVE-2026-12191HIGHComma AI Openpilot Pickle modeld.py pickle.loads deserializationEPSS 0.1%CVE-2025-24005HIGHLocal Privilege Escalation via Vulnerable SSH ScriptEPSS 0.1%CVE-2022-20457MEDIUMIn getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validatiEPSS 0.1%CVE-2022-20542HIGHIn parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation EPSS 0.1%CVE-2022-30754HIGHImplicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities witEPSS 0.1%CVE-2025-21086MEDIUMImproper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticEPSS 0.1%CVE-2022-30756HIGHImplicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with pEPSS 0.1%CVE-2023-28574CRITICALImproper Input Validation in CoreEPSS 0.1%