Weaknesses of type CWE-20

5,418 results

Validação inadequada de entrada

O software recebe dados do usuário ou de fontes externas, mas não verifica ou verifica de forma incompleta se esses dados têm as propriedades necessárias para processar com segurança. Isso permite que entradas malformadas, maliciosas ou inesperadas passem por controles e causem comportamentos indevidos — desde crashes até injeção de código.

Example

Uma aplicação web recebe um parâmetro numérico via GET, mas não valida se é realmente um número inteiro válido antes de usá-lo em uma consulta SQL. Um atacante envia um valor com caracteres especiais (ex: `1' OR '1'='1`), conseguindo injetar código SQL direto no banco de dados.

How to mitigate

Implemente validação rigorosa na entrada: defina o tipo, formato, comprimento e intervalo esperados; rejeite tudo que não se encaixe. Use listas de caracteres permitidos ('whitelist'), escape de dados para o contexto específico (SQL, HTML, URL) e bibliotecas de validação consolidadas. Nunca confie em dados do cliente.

CVE-2023-27496MEDIUMEnvoy may crash when a redirect url without a state param is received in the oauth filterEPSS 0.8%CVE-2023-48608LOWAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.8%CVE-2021-25444—An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.EPSS 0.8%CVE-2022-4032HIGHQuiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short AnswerEPSS 0.8%CVE-2022-31772MEDIUMIBM MQ denial of serviceEPSS 0.8%CVE-2023-36406MEDIUMWindows Hyper-V Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-45062HIGHFrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP FilesEPSS 0.8%CVE-2026-44300HIGHOpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/InjectionEPSS 0.8%CVE-2023-32728MEDIUMCode injection in zabbix_agent2 smart.disk.get caused by smartctl pluginEPSS 0.8%CVE-2022-3767HIGHMissing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every EPSS 0.8%CVE-2024-25090MEDIUMApache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users modeEPSS 0.8%CVE-2016-9494—Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation, potentially leading to denial of serviceEPSS 0.8%CVE-2025-26413HIGHApache Kvrocks: The server was crashed by the negative offsetEPSS 0.8%CVE-2026-53503HIGHThumbor convolution filter allows divide-by-zero in C extension leading to remote DoSEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2021-29507MEDIUMdlt-daemon could crash if there is special character in dlt.confEPSS 0.7%CVE-2025-62222HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-93567HIGHIo.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authorityEPSS 0.7%CVE-2022-29562LOWA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 0.7%CVE-2024-23483HIGHLocal Privilege Escalation via lack of input validationEPSS 0.7%