VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,428)

page 263 of 672
  • CVE-2025-65397MedJan 14, 2026
    risk 0.44cvss 6.8epss 0.00

    An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not…

  • CVE-2025-64993MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation…

  • CVE-2025-64992MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands.…

  • CVE-2025-64991MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands.…

  • CVE-2025-64990MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary…

  • CVE-2025-22432MedDec 8, 2025
    risk 0.44cvss 6.7epss 0.00

    In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed…

  • CVE-2025-10155HigSep 17, 2025
    risk 0.44cvss 7.8epss 0.01

    An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the…

  • CVE-2023-21473MedSep 3, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

  • CVE-2023-21472MedSep 3, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

  • CVE-2025-54642MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54641MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-20197MedMay 7, 2025
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when…

  • CVE-2025-30293MedApr 8, 2025
    risk 0.44cvss 6.8epss 0.01

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized…

  • CVE-2024-39780HigApr 2, 2025
    risk 0.44cvss 7.8epss 0.00

    A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of…

  • CVE-2024-49073MedDec 12, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

  • CVE-2021-30299MedNov 22, 2024
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound access in audio module due to lack of validation of user provided input.

  • CVE-2021-1462MedNov 18, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate privileges on an affected system. To exploit this vulnerability, an attacker would need to have a valid Administrator account on an affected system. The…

  • CVE-2021-34752MedNov 15, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device. This vulnerability is due to…

  • CVE-2024-33031MedNov 4, 2024
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while processing the update SIM PB records request.

  • CVE-2024-23386MedNov 4, 2024
    risk 0.44cvss 6.7epss 0.00

    memory corruption when WiFi display APIs are invoked with large random inputs.