VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 412 of 668
  • CVE-2025-8708MedAug 8, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input…

  • CVE-2025-53471MedJul 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CVE-2025-0424MedFeb 18, 2025
    risk 0.33cvss epss 0.00

    In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript…

  • CVE-2024-31153MedFeb 12, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-0974MedFeb 3, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of…

  • CVE-2021-1464MedNov 15, 2024
    risk 0.33cvss 5.0epss 0.01

    A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affected software has…

  • CVE-2024-51519MedNov 5, 2024
    risk 0.33cvss 5.0epss 0.00

    Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-45031MedOct 24, 2024
    risk 0.33cvss 6.1epss 0.01

    When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in…

  • CVE-2024-0158MedJul 2, 2024
    risk 0.33cvss 5.1epss 0.00

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges

  • CVE-2024-32856MedJun 13, 2024
    risk 0.33cvss 5.1epss 0.00

    Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2024-32653MedApr 22, 2024
    risk 0.33cvss 6.1epss 0.00

    jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This can be exploited to inject arbitrary code into the package name. The vulnerability allows an attacker to execute commands with shell privileges. Version 1.5.0…

  • CVE-2023-7248MedMar 15, 2024
    risk 0.33cvss 5.0epss 0.00

    Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.  The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the…

  • CVE-2024-21448MedMar 12, 2024
    risk 0.33cvss 5.0epss 0.01

    Microsoft Teams for Android Information Disclosure Vulnerability

  • CVE-2024-21374MedFeb 13, 2024
    risk 0.33cvss 5.0epss 0.01

    Microsoft Teams for Android Information Disclosure Vulnerability

  • CVE-2023-40053MedDec 6, 2023
    risk 0.33cvss 5.0epss 0.01

    A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.

  • CVE-2023-39411MedNov 14, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2023-38719MedOct 17, 2023
    risk 0.33cvss 5.1epss 0.00

    IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation on DPF. IBM X-Force ID: 261607.

  • CVE-2023-43799MedOct 4, 2023
    risk 0.33cvss 5.0epss 0.00

    Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system. Moreover, Altair GraphQL Client also does not isolate the context of the renderer process. This affects…

  • CVE-2023-30952MedAug 3, 2023
    risk 0.33cvss 5.0epss 0.00

    A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 .

  • CVE-2023-28060MedJun 23, 2023
    risk 0.33cvss 5.1epss 0.00

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.