CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 445 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8124 | Med | 0.28 | 5.3 | 0.02 | Feb 4, 2020 | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. | ||
| CVE-2020-8122 | Med | 0.28 | 4.3 | 0.01 | Feb 4, 2020 | A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received. | ||
| CVE-2018-1002104 | Med | 0.28 | 5.3 | 0.01 | Jan 14, 2020 | Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly. | ||
| CVE-2019-18995 | Med | 0.28 | 4.3 | 0.02 | Dec 18, 2019 | The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting. | ||
| CVE-2019-8670 | Med | 0.28 | 4.3 | 0.01 | Dec 18, 2019 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing. | ||
| CVE-2019-15971 | Med | 0.28 | 4.3 | 0.00 | Nov 26, 2019 | A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file… | ||
| CVE-2019-5864 | Med | 0.28 | 4.3 | 0.00 | Nov 25, 2019 | Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. | ||
| CVE-2019-13675 | Med | 0.28 | 4.3 | 0.01 | Nov 25, 2019 | Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page. | ||
| CVE-2013-1811 | Med | 0.28 | 4.3 | 0.01 | Nov 7, 2019 | An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". | ||
| CVE-2010-3667 | Med | 0.28 | 5.3 | 0.01 | Nov 4, 2019 | TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element. | ||
| CVE-2013-1930 | Med | 0.28 | 4.3 | 0.01 | Oct 31, 2019 | MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues. | ||
| CVE-2019-6654 | Med | 0.28 | 4.3 | 0.00 | Sep 25, 2019 | On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent system to force… | ||
| CVE-2019-1204 | Med | 0.28 | 4.3 | 0.04 | Aug 14, 2019 | An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a… | ||
| CVE-2019-7899 | Med | 0.28 | 5.3 | 0.01 | Aug 2, 2019 | Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. | ||
| CVE-2019-7898 | Med | 0.28 | 5.3 | 0.01 | Aug 2, 2019 | Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input. | ||
| CVE-2017-18461 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223). | ||
| CVE-2017-18440 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244). | ||
| CVE-2016-10765 | Med | 0.28 | 5.3 | 0.01 | Jul 29, 2019 | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. | ||
| CVE-2019-5839 | Med | 0.28 | 4.3 | 0.01 | Jun 27, 2019 | Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL. | ||
| CVE-2019-0094 | Med | 0.28 | 4.3 | 0.00 | May 17, 2019 | Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access. |
- risk 0.28cvss 5.3epss 0.02
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
- risk 0.28cvss 4.3epss 0.01
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
- risk 0.28cvss 5.3epss 0.01
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
- risk 0.28cvss 4.3epss 0.02
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
- risk 0.28cvss 4.3epss 0.01
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.
- risk 0.28cvss 4.3epss 0.00
A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file…
- risk 0.28cvss 4.3epss 0.00
Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
- risk 0.28cvss 4.3epss 0.01
Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page.
- risk 0.28cvss 4.3epss 0.01
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
- risk 0.28cvss 5.3epss 0.01
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.
- risk 0.28cvss 4.3epss 0.01
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
- risk 0.28cvss 4.3epss 0.00
On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent system to force…
- risk 0.28cvss 4.3epss 0.04
An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a…
- risk 0.28cvss 5.3epss 0.01
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
- risk 0.28cvss 5.3epss 0.01
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.
- risk 0.28cvss 4.3epss 0.01
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).
- risk 0.28cvss 4.3epss 0.01
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
- risk 0.28cvss 5.3epss 0.01
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
- risk 0.28cvss 4.3epss 0.01
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
- risk 0.28cvss 4.3epss 0.00
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.