VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,387)

page 278 of 670
  • CVE-2026-84357MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)

  • CVE-2026-82639HigAug 30, 2026
    risk 0.42cvss 7.5epss 0.00

    NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any…

  • CVE-2026-30064HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-79288MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79260MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79253MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79243MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79123MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79076MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-75975HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.00

    fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6…

  • CVE-2026-2996HigAug 22, 2026
    risk 0.42cvss 7.5epss 0.00

    The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated…

  • CVE-2026-63421HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQL client to provide a negative…

  • CVE-2026-70105MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-53587HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in…

  • CVE-2026-76323MedAug 19, 2026
    risk 0.42cvss 6.4epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could bypass Search Processing Language (SPL) safeguards for risky commands through the Job Details dashboard. The injected SPL could run using…

  • CVE-2026-19509MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter.

  • CVE-2026-15316MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient…

  • CVE-2026-73418HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer…

  • CVE-2026-48436MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires…

  • CVE-2026-71217HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to…