VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,387)

page 290 of 670
  • CVE-2025-21614HigJan 6, 2025
    risk 0.42cvss 7.5epss 0.01

    go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted…

  • CVE-2024-52590MedDec 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they actually exist. These profiles…

  • CVE-2024-52579MedDec 18, 2024
    risk 0.42cvss 6.4epss 0.00

    Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a SSRF attack.It allows an…

  • CVE-2024-55653MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.01

    PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id…

  • CVE-2024-9257MedNov 22, 2024
    risk 0.42cvss 6.5epss 0.01

    Logsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files within sensitive directories on affected installations of Logsign Unified SecOps Platform.…

  • CVE-2024-45422MedNov 19, 2024
    risk 0.42cvss 6.5epss 0.01

    Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.

  • CVE-2021-1482MedNov 15, 2024
    risk 0.42cvss 6.4epss 0.01

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to sensitive information on an affected system. This vulnerability is due to insufficient…

  • CVE-2022-2232HigNov 14, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.

  • CVE-2024-50305HigNov 14, 2024
    risk 0.42cvss 7.5epss 0.01

    Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

  • CVE-2024-38479HigNov 14, 2024
    risk 0.42cvss 7.5epss 0.01

    Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

  • CVE-2024-32048MedNov 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-24984MedNov 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-8936MedNov 13, 2024
    risk 0.42cvss 6.5epss 0.01

    CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.

  • CVE-2023-1973HigNov 7, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

  • CVE-2024-43561MedOct 8, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mobile Broadband Driver Denial of Service Vulnerability

  • CVE-2024-43558MedOct 8, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mobile Broadband Driver Denial of Service Vulnerability

  • CVE-2024-43557MedOct 8, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mobile Broadband Driver Denial of Service Vulnerability

  • CVE-2024-43542MedOct 8, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mobile Broadband Driver Denial of Service Vulnerability

  • CVE-2024-43540MedOct 8, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mobile Broadband Driver Denial of Service Vulnerability

  • CVE-2024-43538MedOct 8, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mobile Broadband Driver Denial of Service Vulnerability