Weaknesses of type CWE-20

5,456 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2025-48623HIGHIn init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalatiEPSS 0.1%CVE-2024-0022MEDIUMIn multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another usEPSS 0.1%CVE-2024-23706HIGHIn multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local eEPSS 0.1%CVE-2026-77797LOWVelociraptor Prefetch parser out of boundsEPSS 0.1%CVE-2026-27765MEDIUMImproper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User ApplicationEPSS 0.1%CVE-2026-21089MEDIUMImproper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-ofEPSS 0.1%CVE-2026-17503MEDIUMThis Power System update is being released to addressEPSS 0.1%CVE-2025-68964MEDIUMData verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-20913MEDIUMImproper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escEPSS 0.1%CVE-2025-29936HIGHImproper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentiEPSS 0.1%CVE-2026-7990HIGHInsufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to performEPSS 0.1%CVE-2024-58044HIGHPermission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect avaEPSS 0.1%CVE-2026-13849HIGHInsufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to poteEPSS 0.1%CVE-2026-7997HIGHInsufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local attacker to perform OS-EPSS 0.1%CVE-2025-14963MEDIUMA vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevatedEPSS 0.1%CVE-2024-38420HIGHImproper Input Validation in HypervisorEPSS 0.1%CVE-2024-43052HIGHImproper Input Validation in Video Analytics and ProcessingEPSS 0.1%CVE-2026-34855MEDIUMOut-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and cEPSS 0.1%CVE-2024-38413MEDIUMImproper Input Validation in Computer VisionEPSS 0.1%CVE-2021-25500HIGHA missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.EPSS 0.1%