CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,429)
page 239 of 672| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-20318 | Hig | 0.48 | 7.4 | 0.00 | Mar 13, 2024 | A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network processor to reset, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling… | ||
| CVE-2024-23842 | Hig | 0.48 | 7.4 | 0.01 | Jan 23, 2024 | Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. | ||
| CVE-2024-22772 | Hig | 0.48 | 7.4 | 0.01 | Jan 23, 2024 | Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. | ||
| CVE-2024-22771 | Hig | 0.48 | 7.4 | 0.01 | Jan 23, 2024 | Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. | ||
| CVE-2024-22770 | Hig | 0.48 | 7.4 | 0.01 | Jan 23, 2024 | Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. | ||
| CVE-2024-22769 | Hig | 0.48 | 7.4 | 0.01 | Jan 23, 2024 | Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. | ||
| CVE-2024-22768 | Hig | 0.48 | 7.4 | 0.01 | Jan 23, 2024 | Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. | ||
| CVE-2024-0507 | Med | 0.48 | 6.5 | 0.66 | Jan 16, 2024 | An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3,… | ||
| CVE-2023-4586 | Hig | 0.48 | 7.4 | 0.01 | Oct 4, 2023 | A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. | ||
| CVE-2023-22382 | Hig | 0.48 | 7.4 | 0.00 | Oct 3, 2023 | Weak configuration in Automotive while VM is processing a listener request from TEE. | ||
| CVE-2023-36762 | Hig | 0.48 | 7.3 | 0.01 | Sep 12, 2023 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2023-20169 | Hig | 0.48 | 7.4 | 0.00 | Aug 23, 2023 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS… | ||
| CVE-2023-36873 | Hig | 0.48 | 7.4 | 0.01 | Aug 8, 2023 | .NET Framework Spoofing Vulnerability | ||
| CVE-2023-24950 | Med | 0.48 | 6.5 | 0.67 | May 9, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2023-30535 | Hig | 0.48 | 7.3 | 0.02 | Apr 14, 2023 | Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An attacker could set up a malicious, publicly accessible server… | ||
| CVE-2023-1250 | Hig | 0.48 | 7.4 | 0.00 | Mar 20, 2023 | Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This… | ||
| CVE-2022-33964 | Hig | 0.48 | 7.4 | 0.01 | Feb 16, 2023 | Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | ||
| CVE-2023-22934 | Hig | 0.48 | 7.3 | 0.01 | Feb 14, 2023 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a… | ||
| CVE-2022-25906 | Hig | 0.48 | 7.4 | 0.01 | Feb 1, 2023 | All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function. | ||
| CVE-2022-43566 | Hig | 0.48 | 7.3 | 0.01 | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions to bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards… |
- risk 0.48cvss 7.4epss 0.00
A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network processor to reset, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling…
- risk 0.48cvss 7.4epss 0.01
Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- risk 0.48cvss 7.4epss 0.01
Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- risk 0.48cvss 7.4epss 0.01
Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- risk 0.48cvss 7.4epss 0.01
Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- risk 0.48cvss 7.4epss 0.01
Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- risk 0.48cvss 7.4epss 0.01
Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- risk 0.48cvss 6.5epss 0.66
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3,…
- risk 0.48cvss 7.4epss 0.01
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
- risk 0.48cvss 7.4epss 0.00
Weak configuration in Automotive while VM is processing a listener request from TEE.
- risk 0.48cvss 7.3epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.48cvss 7.4epss 0.00
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS…
- risk 0.48cvss 7.4epss 0.01
.NET Framework Spoofing Vulnerability
- risk 0.48cvss 6.5epss 0.67
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.48cvss 7.3epss 0.02
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An attacker could set up a malicious, publicly accessible server…
- risk 0.48cvss 7.4epss 0.00
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This…
- risk 0.48cvss 7.4epss 0.01
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- risk 0.48cvss 7.3epss 0.01
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a…
- risk 0.48cvss 7.4epss 0.01
All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.
- risk 0.48cvss 7.3epss 0.01
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions to bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards…