VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 360 of 668
  • CVE-2025-26429MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-27537MedAug 12, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2025-43195MedJul 30, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

  • CVE-2025-47182MedJul 11, 2025
    risk 0.36cvss 5.6epss 0.00

    Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

  • CVE-2025-7099MedJul 7, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation of the argument db_host leads to…

  • CVE-2025-52569MedJun 25, 2025
    risk 0.36cvss epss 0.00

    GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the `repo_name` field.…

  • CVE-2025-50178MedJun 25, 2025
    risk 0.36cvss epss 0.00

    GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certain functions. In the `GitForge.get_repo` function for GitHub, the user can provide any string for the owner and repo fields. These…

  • CVE-2025-5498MedJun 3, 2025
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. The manipulation of the…

  • CVE-2025-48490MedMay 30, 2025
    risk 0.36cvss epss 0.01

    Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such…

  • CVE-2025-46836MedMay 14, 2025
    risk 0.36cvss 6.6epss 0.00

    net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure…

  • CVE-2025-3622MedApr 15, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.

  • CVE-2025-29821MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.01

    Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

  • CVE-2025-24191MedMar 31, 2025
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.

  • CVE-2024-10083MedFeb 13, 2025
    risk 0.36cvss 5.5epss 0.00

    CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.

  • CVE-2025-26358MedFeb 12, 2025
    risk 0.36cvss 5.5epss 0.01

    A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.

  • CVE-2025-21126MedFeb 11, 2025
    risk 0.36cvss 5.5epss 0.00

    InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, resulting in a…

  • CVE-2025-21284MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Virtual Trusted Platform Module Denial of Service Vulnerability

  • CVE-2025-21280MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Virtual Trusted Platform Module Denial of Service Vulnerability

  • CVE-2024-36284MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2024-21949MedNov 12, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.