VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 123 of 668
  • CVE-2026-26143HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-14963HigFeb 24, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process…

  • CVE-2025-48647HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-20951HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-61916HigJan 5, 2026
    risk 0.51cvss 7.9epss 0.00

    Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into…

  • CVE-2025-36932HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-62571HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62455HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48638HigDec 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48632HigDec 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2025-48624HigDec 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48623HigDec 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48612HigDec 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2025-48566HigDec 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48525HigDec 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a companion device due to improper input validation. This could lead to local escalation of privilege with no additional execution…

  • CVE-2025-43472HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to gain root privileges.

  • CVE-2025-59207HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59187HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55692HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47314HigSep 24, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing data sent by FE driver.