VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,428)

page 247 of 672
  • CVE-2024-0161HigMar 13, 2024
    risk 0.47cvss 7.2epss 0.00

    Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.

  • CVE-2024-27613HigMar 8, 2024
    risk 0.47cvss 7.3epss 0.00

    Numbas editor before 7.3 mishandles reading of themes and extensions.

  • CVE-2023-42661HigMar 7, 2024
    risk 0.47cvss 7.2epss 0.01

    JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.

  • CVE-2024-20034HigMar 4, 2024
    risk 0.47cvss 7.2epss 0.00

    In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08488849; Issue ID: ALPS08488849.

  • CVE-2021-33161HigFeb 23, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-4551HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated users to inject…

  • CVE-2023-39509HigDec 18, 2023
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.

  • CVE-2023-32641HigNov 14, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.

  • CVE-2023-5624HigOct 26, 2023
    risk 0.47cvss 7.2epss 0.00

    Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.

  • CVE-2023-31008HigSep 20, 2023
    risk 0.47cvss 7.3epss 0.00

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of services, escalation of privileges, and information disclosure.

  • CVE-2023-38156HigSep 12, 2023
    risk 0.47cvss 7.2epss 0.02

    Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability

  • CVE-2021-36021HigSep 6, 2023
    risk 0.47cvss 7.2epss 0.02

    Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability…

  • CVE-2015-2202HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

  • CVE-2022-38102HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2023-21251HigJul 13, 2023
    risk 0.47cvss 7.3epss 0.00

    In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-2454HigJun 9, 2023
    risk 0.47cvss 7.2epss 0.01

    schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.

  • CVE-2023-34102HigJun 5, 2023
    risk 0.47cvss 8.3epss 0.02

    Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or…

  • CVE-2022-32766HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-29410HigApr 18, 2023
    risk 0.47cvss 7.2epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.

  • CVE-2023-26293HigApr 11, 2023
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6),…