CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 412 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-8708 | Med | 0.33 | 5.0 | 0.00 | Aug 8, 2025 | A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input… | ||
| CVE-2025-53471 | Med | 0.33 | 5.1 | 0.00 | Jul 11, 2025 | Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. | ||
| CVE-2025-0424 | Med | 0.33 | — | 0.00 | Feb 18, 2025 | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript… | ||
| CVE-2024-31153 | Med | 0.33 | 5.0 | 0.00 | Feb 12, 2025 | Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2025-0974 | Med | 0.33 | 5.0 | 0.00 | Feb 3, 2025 | A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of… | ||
| CVE-2021-1464 | Med | 0.33 | 5.0 | 0.01 | Nov 15, 2024 | A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affected software has… | ||
| CVE-2024-51519 | Med | 0.33 | 5.0 | 0.00 | Nov 5, 2024 | Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-45031 | Med | 0.33 | 6.1 | 0.01 | Oct 24, 2024 | When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in… | ||
| CVE-2024-0158 | Med | 0.33 | 5.1 | 0.00 | Jul 2, 2024 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | ||
| CVE-2024-32856 | Med | 0.33 | 5.1 | 0.00 | Jun 13, 2024 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | ||
| CVE-2024-32653 | Med | 0.33 | 6.1 | 0.00 | Apr 22, 2024 | jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This can be exploited to inject arbitrary code into the package name. The vulnerability allows an attacker to execute commands with shell privileges. Version 1.5.0… | ||
| CVE-2023-7248 | Med | 0.33 | 5.0 | 0.00 | Mar 15, 2024 | Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the… | ||
| CVE-2024-21448 | Med | 0.33 | 5.0 | 0.01 | Mar 12, 2024 | Microsoft Teams for Android Information Disclosure Vulnerability | ||
| CVE-2024-21374 | Med | 0.33 | 5.0 | 0.01 | Feb 13, 2024 | Microsoft Teams for Android Information Disclosure Vulnerability | ||
| CVE-2023-40053 | Med | 0.33 | 5.0 | 0.01 | Dec 6, 2023 | A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously. | ||
| CVE-2023-39411 | Med | 0.33 | 5.0 | 0.00 | Nov 14, 2023 | Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access. | ||
| CVE-2023-38719 | Med | 0.33 | 5.1 | 0.00 | Oct 17, 2023 | IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation on DPF. IBM X-Force ID: 261607. | ||
| CVE-2023-43799 | Med | 0.33 | 5.0 | 0.00 | Oct 4, 2023 | Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system. Moreover, Altair GraphQL Client also does not isolate the context of the renderer process. This affects… | ||
| CVE-2023-30952 | Med | 0.33 | 5.0 | 0.00 | Aug 3, 2023 | A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 . | ||
| CVE-2023-28060 | Med | 0.33 | 5.1 | 0.00 | Jun 23, 2023 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. |
- risk 0.33cvss 5.0epss 0.00
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input…
- risk 0.33cvss 5.1epss 0.00
Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- risk 0.33cvss —epss 0.00
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript…
- risk 0.33cvss 5.0epss 0.00
Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.33cvss 5.0epss 0.00
A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of…
- risk 0.33cvss 5.0epss 0.01
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affected software has…
- risk 0.33cvss 5.0epss 0.00
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 6.1epss 0.01
When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in…
- risk 0.33cvss 5.1epss 0.00
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
- risk 0.33cvss 5.1epss 0.00
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
- risk 0.33cvss 6.1epss 0.00
jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This can be exploited to inject arbitrary code into the package name. The vulnerability allows an attacker to execute commands with shell privileges. Version 1.5.0…
- risk 0.33cvss 5.0epss 0.00
Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the…
- risk 0.33cvss 5.0epss 0.01
Microsoft Teams for Android Information Disclosure Vulnerability
- risk 0.33cvss 5.0epss 0.01
Microsoft Teams for Android Information Disclosure Vulnerability
- risk 0.33cvss 5.0epss 0.01
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.
- risk 0.33cvss 5.0epss 0.00
Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
- risk 0.33cvss 5.1epss 0.00
IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation on DPF. IBM X-Force ID: 261607.
- risk 0.33cvss 5.0epss 0.00
Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system. Moreover, Altair GraphQL Client also does not isolate the context of the renderer process. This affects…
- risk 0.33cvss 5.0epss 0.00
A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 .
- risk 0.33cvss 5.1epss 0.00
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.