CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,387)
page 290 of 670| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21614 | Hig | 0.42 | 7.5 | 0.01 | Jan 6, 2025 | go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted… | ||
| CVE-2024-52590 | Med | 0.42 | 6.5 | 0.00 | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they actually exist. These profiles… | ||
| CVE-2024-52579 | Med | 0.42 | 6.4 | 0.00 | Dec 18, 2024 | Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a SSRF attack.It allows an… | ||
| CVE-2024-55653 | Med | 0.42 | 6.5 | 0.01 | Dec 10, 2024 | PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id… | ||
| CVE-2024-9257 | Med | 0.42 | 6.5 | 0.01 | Nov 22, 2024 | Logsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files within sensitive directories on affected installations of Logsign Unified SecOps Platform.… | ||
| CVE-2024-45422 | Med | 0.42 | 6.5 | 0.01 | Nov 19, 2024 | Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2021-1482 | Med | 0.42 | 6.4 | 0.01 | Nov 15, 2024 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to sensitive information on an affected system. This vulnerability is due to insufficient… | ||
| CVE-2022-2232 | Hig | 0.42 | 7.5 | 0.01 | Nov 14, 2024 | A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions. | ||
| CVE-2024-50305 | Hig | 0.42 | 7.5 | 0.01 | Nov 14, 2024 | Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue. | ||
| CVE-2024-38479 | Hig | 0.42 | 7.5 | 0.01 | Nov 14, 2024 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue. | ||
| CVE-2024-32048 | Med | 0.42 | 6.5 | 0.00 | Nov 13, 2024 | Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | ||
| CVE-2024-24984 | Med | 0.42 | 6.5 | 0.00 | Nov 13, 2024 | Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | ||
| CVE-2024-8936 | Med | 0.42 | 6.5 | 0.01 | Nov 13, 2024 | CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory. | ||
| CVE-2023-1973 | Hig | 0.42 | 7.5 | 0.01 | Nov 7, 2024 | A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory. | ||
| CVE-2024-43561 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43558 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43557 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43542 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43540 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-43538 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability |
- risk 0.42cvss 7.5epss 0.01
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted…
- risk 0.42cvss 6.5epss 0.00
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they actually exist. These profiles…
- risk 0.42cvss 6.4epss 0.00
Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a SSRF attack.It allows an…
- risk 0.42cvss 6.5epss 0.01
PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id…
- risk 0.42cvss 6.5epss 0.01
Logsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files within sensitive directories on affected installations of Logsign Unified SecOps Platform.…
- risk 0.42cvss 6.5epss 0.01
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.42cvss 6.4epss 0.01
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to sensitive information on an affected system. This vulnerability is due to insufficient…
- risk 0.42cvss 7.5epss 0.01
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
- risk 0.42cvss 7.5epss 0.01
Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
- risk 0.42cvss 7.5epss 0.01
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
- risk 0.42cvss 6.5epss 0.00
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- risk 0.42cvss 6.5epss 0.00
Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- risk 0.42cvss 6.5epss 0.01
CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.
- risk 0.42cvss 7.5epss 0.01
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability