CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,545)
page 16 of 678| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-45163 | — | Cri | 0.64 | 9.9 | 0.01 | Nov 6, 2023 | The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This… | |
| CVE-2023-45161 | — | Cri | 0.64 | 9.9 | 0.01 | Nov 6, 2023 | The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This… | |
| CVE-2023-41355 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2023 | Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of… | ||
| CVE-2023-35349 | Cri | 0.64 | 9.8 | 0.03 | Oct 10, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-32485 | Cri | 0.64 | 9.8 | 0.01 | Oct 5, 2023 | Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability… | ||
| CVE-2023-36619 | Cri | 0.64 | 9.8 | 0.04 | Oct 4, 2023 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users. | ||
| CVE-2022-48605 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. | ||
| CVE-2023-41748 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | ||
| CVE-2023-41746 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | ||
| CVE-2023-25915 | Cri | 0.64 | 9.9 | 0.01 | Aug 21, 2023 | Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system. | ||
| CVE-2023-39405 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2023 | Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges. | ||
| CVE-2023-35367 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2023-35366 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2023-35365 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2023-32057 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-32015 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-34152 | Cri | 0.64 | 9.8 | 0.08 | May 30, 2023 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. | ||
| CVE-2023-32321 | Cri | 0.64 | 9.8 | 0.02 | May 26, 2023 | CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the… | ||
| CVE-2022-47937 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2023 | Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are… | ||
| CVE-2023-31039 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2023 | Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the… |
- risk 0.64cvss 9.9epss 0.01
The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This…
- risk 0.64cvss 9.9epss 0.01
The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This…
- risk 0.64cvss 9.8epss 0.01
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of…
- risk 0.64cvss 9.8epss 0.03
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability…
- risk 0.64cvss 9.8epss 0.04
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.
- risk 0.64cvss 9.8epss 0.00
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.01
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
- risk 0.64cvss 9.8epss 0.01
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
- risk 0.64cvss 9.9epss 0.01
Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.
- risk 0.64cvss 9.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.08
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
- risk 0.64cvss 9.8epss 0.02
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the…
- risk 0.64cvss 9.8epss 0.02
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are…
- risk 0.64cvss 9.8epss 0.02
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the…