Weaknesses of type CWE-20

5,456 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2021-25511MEDIUMAn improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path EPSS 0.1%CVE-2024-45577HIGHImproper Input Validation in Camera DriverEPSS 0.1%CVE-2021-25510MEDIUMAn improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.EPSS 0.1%CVE-2024-45579HIGHImproper Input Validation in Camera DriverEPSS 0.1%CVE-2024-51520MEDIUMVulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.1%CVE-2024-45444MEDIUMAccess permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confEPSS 0.1%CVE-2022-20019MEDIUMIn libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information discloEPSS 0.1%CVE-2025-31948MEDIUMImproper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applications may allow a deEPSS 0.1%CVE-2023-20634MEDIUMIn widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege withEPSS 0.1%CVE-2026-21088MEDIUMImproper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write EPSS 0.1%CVE-2024-51530MEDIUMLaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.1%CVE-2023-22382HIGHImproper Input Validation in AutomotiveEPSS 0.1%CVE-2024-31310HIGHIn newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill EPSS 0.1%CVE-2026-21086MEDIUMImproper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.EPSS 0.1%CVE-2026-101131MEDIUMdeepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decisionEPSS 0.1%CVE-2026-11241HIGHInsufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment EPSS 0.1%CVE-2026-58941HIGHIn multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local esEPSS 0.1%CVE-2021-25468MEDIUMA possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to readEPSS 0.1%CVE-2024-51514MEDIUMVulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect servEPSS 0.1%CVE-2024-51519MEDIUMVulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.1%