VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 473 of 668
  • CVE-2024-25571LowFeb 12, 2025
    risk 0.15cvss 2.3epss 0.00

    Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2021-21726LowMar 12, 2021
    risk 0.15cvss 2.3epss 0.00

    Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges can cause process exception by repeatedly inputting illegal parameters. This…

  • CVE-2020-15186LowSep 17, 2020
    risk 0.15cvss 3.4epss 0.01

    In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin author could use characters in a plugin name that would result in unexpected behavior, such as duplicating the name of another plugin or spoofing the output to…

  • CVE-2018-20893LowAug 1, 2019
    risk 0.15cvss 2.3epss 0.00

    cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).

  • CVE-2026-34086LowMay 11, 2026
    risk 0.14cvss epss 0.00

    Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2.

  • CVE-2026-35377LowApr 22, 2026
    risk 0.14cvss 3.3epss 0.00

    A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when utilizing the -S (split-string) option. In GNU env, backslashes within single quotes are treated literally (with the exceptions of \\ and \'). However, the uutils…

  • CVE-2026-4519LowMar 20, 2026
    risk 0.14cvss 3.3epss 0.00

    The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

  • CVE-2026-4407LowMar 18, 2026
    risk 0.14cvss epss 0.00

    Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color spaces.

  • CVE-2025-13462LowMar 12, 2026
    risk 0.14cvss 3.3epss 0.00

    The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to…

  • CVE-2024-22117LowNov 26, 2024
    risk 0.14cvss 2.2epss 0.00

    When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value…

  • CVE-2024-24973LowAug 14, 2024
    risk 0.14cvss 2.2epss 0.00

    Improper input validation for some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-45469LowNov 14, 2023
    risk 0.14cvss 2.2epss 0.00

    Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-42431LowOct 30, 2023
    risk 0.14cvss 2.1epss 0.00

    Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.

  • CVE-2022-39259LowOct 21, 2022
    risk 0.14cvss 3.3epss 0.00

    jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prior to 1.4.5 are subject to a Denial of Service when opening zip files with HTML sequences. This issue has been patched in version 1.4.5. There are no known…

  • CVE-2020-16237LowAug 21, 2020
    risk 0.14cvss 2.1epss 0.00

    Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

  • CVE-2019-14671LowAug 5, 2019
    risk 0.14cvss 3.3epss 0.00

    Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.

  • CVE-2026-13480LowAug 26, 2026
    risk 0.13cvss 3.1epss 0.00

    The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain before each access. The loop's only bound is rx_pos < len;…

  • CVE-2026-12566LowJun 17, 2026
    risk 0.13cvss 3.1epss 0.00

    The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the…

  • CVE-2026-11465LowJun 7, 2026
    risk 0.13cvss 3.1epss 0.00

    A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors. The attack may…

  • CVE-2026-33436LowApr 17, 2026
    risk 0.13cvss 3.1epss 0.00

    Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames directly into HTML using unsafe methods like innerHTML without sanitization. An attacker can craft…