CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 360 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-26429 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2025 | In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2025-27537 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2025 | Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | ||
| CVE-2025-43195 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2025 | An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data. | ||
| CVE-2025-47182 | Med | 0.36 | 5.6 | 0.00 | Jul 11, 2025 | Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-7099 | Med | 0.36 | 5.6 | 0.00 | Jul 7, 2025 | A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation of the argument db_host leads to… | ||
| CVE-2025-52569 | Med | 0.36 | — | 0.00 | Jun 25, 2025 | GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the `repo_name` field.… | ||
| CVE-2025-50178 | Med | 0.36 | — | 0.00 | Jun 25, 2025 | GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certain functions. In the `GitForge.get_repo` function for GitHub, the user can provide any string for the owner and repo fields. These… | ||
| CVE-2025-5498 | Med | 0.36 | 5.5 | 0.01 | Jun 3, 2025 | A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. The manipulation of the… | ||
| CVE-2025-48490 | Med | 0.36 | — | 0.01 | May 30, 2025 | Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such… | ||
| CVE-2025-46836 | Med | 0.36 | 6.6 | 0.00 | May 14, 2025 | net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure… | ||
| CVE-2025-3622 | Med | 0.36 | 5.5 | 0.00 | Apr 15, 2025 | A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization. | ||
| CVE-2025-29821 | Med | 0.36 | 5.5 | 0.01 | Apr 8, 2025 | Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24191 | Med | 0.36 | 5.5 | 0.00 | Mar 31, 2025 | The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system. | ||
| CVE-2024-10083 | — | Med | 0.36 | 5.5 | 0.00 | Feb 13, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input. | |
| CVE-2025-26358 | Med | 0.36 | 5.5 | 0.01 | Feb 12, 2025 | A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests. | ||
| CVE-2025-21126 | Med | 0.36 | 5.5 | 0.00 | Feb 11, 2025 | InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, resulting in a… | ||
| CVE-2025-21284 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | ||
| CVE-2025-21280 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | ||
| CVE-2024-36284 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2024 | Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | ||
| CVE-2024-21949 | Med | 0.36 | 5.5 | 0.00 | Nov 12, 2024 | Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash. |
- risk 0.36cvss 5.5epss 0.00
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
- risk 0.36cvss 5.5epss 0.00
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.
- risk 0.36cvss 5.6epss 0.00
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.6epss 0.00
A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation of the argument db_host leads to…
- risk 0.36cvss —epss 0.00
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the `repo_name` field.…
- risk 0.36cvss —epss 0.00
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certain functions. In the `GitForge.get_repo` function for GitHub, the user can provide any string for the owner and repo fields. These…
- risk 0.36cvss 5.5epss 0.01
A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. The manipulation of the…
- risk 0.36cvss —epss 0.01
Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such…
- risk 0.36cvss 6.6epss 0.00
net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure…
- risk 0.36cvss 5.5epss 0.00
A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.
- risk 0.36cvss 5.5epss 0.01
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.
- risk 0.36cvss 5.5epss 0.00
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
- risk 0.36cvss 5.5epss 0.01
A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.
- risk 0.36cvss 5.5epss 0.00
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, resulting in a…
- risk 0.36cvss 5.5epss 0.01
Windows Virtual Trusted Platform Module Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Virtual Trusted Platform Module Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.00
Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
- risk 0.36cvss 5.5epss 0.00
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.