CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,428)
page 264 of 672| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-22065 | Med | 0.44 | 6.8 | 0.01 | Oct 29, 2024 | There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands. | ||
| CVE-2024-43526 | Med | 0.44 | 6.8 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | ||
| CVE-2024-43525 | Med | 0.44 | 6.8 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | ||
| CVE-2024-43523 | Med | 0.44 | 6.8 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | ||
| CVE-2024-25008 | Med | 0.44 | 6.8 | 0.00 | Aug 16, 2024 | Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated… | ||
| CVE-2023-24062 | Med | 0.44 | 6.8 | 0.00 | Aug 8, 2024 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to… | ||
| CVE-2024-27386 | Med | 0.44 | 6.7 | 0.00 | Jul 9, 2024 | A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite. | ||
| CVE-2024-27385 | Med | 0.44 | 6.7 | 0.00 | Jul 9, 2024 | A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which can lead to heap overwrite. | ||
| CVE-2024-34693 | Med | 0.44 | 6.8 | 0.02 | Jun 20, 2024 | Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile,… | ||
| CVE-2024-30002 | Med | 0.44 | 6.8 | 0.01 | May 14, 2024 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | ||
| CVE-2024-29998 | Med | 0.44 | 6.8 | 0.01 | May 14, 2024 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | ||
| CVE-2024-20056 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185. | ||
| CVE-2023-36505 | Med | 0.44 | 6.8 | 0.01 | Apr 17, 2024 | Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24. | ||
| CVE-2024-28897 | Med | 0.44 | 6.8 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-26253 | Med | 0.44 | 6.8 | 0.01 | Apr 9, 2024 | Windows rndismp6.sys Remote Code Execution Vulnerability | ||
| CVE-2024-31212 | Med | 0.44 | 6.7 | 0.01 | Apr 4, 2024 | InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data… | ||
| CVE-2023-32633 | Med | 0.44 | 6.7 | 0.00 | Mar 14, 2024 | Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2024-24549 | Hig | 0.44 | 7.5 | 0.23 | Mar 13, 2024 | Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers… | ||
| CVE-2024-27612 | Med | 0.44 | 6.2 | 0.11 | Mar 8, 2024 | Numbas editor before 7.3 mishandles editing of themes and extensions. | ||
| CVE-2024-24696 | Med | 0.44 | 6.8 | 0.01 | Feb 14, 2024 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. |
- risk 0.44cvss 6.8epss 0.01
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.00
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated…
- risk 0.44cvss 6.8epss 0.00
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to…
- risk 0.44cvss 6.7epss 0.00
A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.
- risk 0.44cvss 6.7epss 0.00
A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which can lead to heap overwrite.
- risk 0.44cvss 6.8epss 0.02
Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile,…
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.00
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.
- risk 0.44cvss 6.8epss 0.01
Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24.
- risk 0.44cvss 6.8epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows rndismp6.sys Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.01
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data…
- risk 0.44cvss 6.7epss 0.00
Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.44cvss 7.5epss 0.23
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers…
- risk 0.44cvss 6.2epss 0.11
Numbas editor before 7.3 mishandles editing of themes and extensions.
- risk 0.44cvss 6.8epss 0.01
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.