VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 118 of 668
  • CVE-2024-45802HigOct 28, 2024
    risk 0.52cvss 7.5epss 0.48

    Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service…

  • CVE-2024-30092HigOct 8, 2024
    risk 0.52cvss 8.0epss 0.01

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2024-3829CriJun 3, 2024
    risk 0.52cvss 9.1epss 0.01

    qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulnerability by manipulating snapshot files to include symlinks, leading to arbitrary file read by adding a symlink that points to a…

  • CVE-2024-25290HigMay 2, 2024
    risk 0.52cvss 8.0epss 0.01

    An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.

  • CVE-2024-3646HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this vulnerability required access…

  • CVE-2024-26240HigApr 9, 2024
    risk 0.52cvss 8.0epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-26189HigApr 9, 2024
    risk 0.52cvss 8.0epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-2469HigMar 20, 2024
    risk 0.52cvss 8.0epss 0.02

    An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.17, 3.9.12, 3.10.9, 3.11.7 and 3.12.1. This…

  • CVE-2024-29027CriMar 19, 2024
    risk 0.52cvss 9.0epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, calling an invalid Parse Server Cloud Function name or Cloud Job name crashes the server and may allow for code injection, internal…

  • CVE-2024-1354HigFeb 13, 2024
    risk 0.52cvss 8.0epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configuration file. Exploitation of this vulnerability required…

  • CVE-2024-0057CriJan 9, 2024
    risk 0.52cvss 9.1epss 0.03

    NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability

  • CVE-2023-36021HigNov 14, 2023
    risk 0.52cvss 8.0epss 0.02

    Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability

  • CVE-2023-40062HigNov 1, 2023
    risk 0.52cvss 8.0epss 0.03

    SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.

  • CVE-2023-25530HigSep 20, 2023
    risk 0.52cvss 8.0epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in the KVM service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

  • CVE-2022-46365CriMay 1, 2023
    risk 0.52cvss 9.1epss 0.01

    Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow…

  • CVE-2022-46303HigFeb 20, 2023
    risk 0.52cvss 8.0epss 0.01

    Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as LDAP administrators in certain scenarios, to perform arbitrary commands within the context of the…

  • CVE-2023-21818HigFeb 14, 2023
    risk 0.52cvss 7.5epss 0.43

    Windows Secure Channel Denial of Service Vulnerability

  • CVE-2022-35924CriAug 2, 2022
    risk 0.52cvss 9.1epss 0.01

    NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a comma-separated list of…

  • CVE-2022-30232HigJun 2, 2022
    risk 0.52cvss 8.0epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart,…

  • CVE-2021-26631HigMay 19, 2022
    risk 0.52cvss 8.0epss 0.01

    Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the total order amount into a negative number and then pay for the order.