VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 358 of 668
  • CVE-2026-70323MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70322MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70320MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70319MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70318MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70316MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70314MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70312MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

  • CVE-2026-43714MedJul 27, 2026
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. A malicious app may be able to access protected…

  • CVE-2026-50012MedJul 16, 2026
    risk 0.36cvss 5.5epss 0.01

    Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the…

  • CVE-2026-48353MedJul 14, 2026
    risk 0.36cvss 5.5epss 0.00

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue…

  • CVE-2026-13929MedJun 30, 2026
    risk 0.36cvss 5.5epss 0.00

    Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)

  • CVE-2026-43722MedJun 29, 2026
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2. An app may be able to leak sensitive kernel state.

  • CVE-2026-9212MedJun 9, 2026
    risk 0.36cvss epss 0.00

    Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

  • CVE-2026-28578MedJun 1, 2026
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0085MedJun 1, 2026
    risk 0.36cvss 5.5epss 0.00

    In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0070MedJun 1, 2026
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-0018MedJun 1, 2026
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-48651MedApr 6, 2026
    risk 0.36cvss 5.5epss 0.00

    In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-28852MedMar 25, 2026
    risk 0.36cvss 5.5epss 0.00

    A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause a denial-of-service.