VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 104 of 668
  • CVE-2025-0052HigJun 10, 2025
    risk 0.54cvss epss 0.00

    Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.

  • CVE-2025-1087CriMay 9, 2025
    risk 0.54cvss epss 0.01

    Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to…

  • CVE-2025-4377HigMay 9, 2025
    risk 0.54cvss epss 0.01

    Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem.  Logview is accessible on Pro Cloud Server Configuration interface.…

  • CVE-2023-49291CriDec 5, 2023
    risk 0.54cvss 9.3epss 0.01

    tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `github.event.pull_request.head.ref` and `github.head_ref` context variables within a GitHub Actions…

  • CVE-2023-6012HigNov 8, 2023
    risk 0.54cvss 8.3epss 0.01

    An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.

  • CVE-2023-5044HigOct 25, 2023
    risk 0.54cvss 7.6epss 0.57

    Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

  • CVE-2023-29464HigOct 13, 2023
    risk 0.54cvss 8.2epss 0.10

    FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure.…

  • CVE-2023-31009HigSep 20, 2023
    risk 0.54cvss 8.3epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

  • CVE-2023-25533HigSep 20, 2023
    risk 0.54cvss 8.3epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to information disclosure, code execution, and escalation of privileges.

  • CVE-2023-38495HigJul 27, 2023
    risk 0.54cvss 8.3epss 0.01

    Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an…

  • CVE-2023-3466HigJul 19, 2023
    risk 0.54cvss 8.3epss 0.03

    Reflected Cross-Site Scripting (XSS)

  • CVE-2023-0683HigMay 1, 2023
    risk 0.54cvss 8.3epss 0.01

    A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.

  • CVE-2022-39353CriNov 2, 2022
    risk 0.54cvss 9.4epss 0.01

    xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the `childNodes` collection of the `Document`,…

  • CVE-2021-22289HigAug 11, 2022
    risk 0.54cvss 8.3epss 0.01

    Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.

  • CVE-2022-36450HigJul 25, 2022
    risk 0.54cvss 8.0epss 0.20

    Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.

  • CVE-2022-35404HigJul 18, 2022
    risk 0.54cvss 8.2epss 0.03

    ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.

  • CVE-2022-24711CriFeb 28, 2022
    risk 0.54cvss 9.4epss 0.01

    CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for…

  • CVE-2021-21968HigFeb 4, 2022
    risk 0.54cvss 8.3epss 0.01

    A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

  • CVE-2021-36032HigSep 1, 2021
    risk 0.54cvss 8.3epss 0.02

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve…

  • CVE-2021-23853HigJun 9, 2021
    risk 0.54cvss 8.3epss 0.01

    In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.