VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 534 of 668
  • CVE-2023-46116CriDec 15, 2023
    risk 0.00cvss 9.3epss 0.01

    Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.12, it correctly blocks the `file:` URL scheme, which can be used by malicious actors to gain code execution on a victims computer,…

  • CVE-2023-41268MedDec 6, 2023
    risk 0.00cvss 5.3epss 0.01

    Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: from 3.0.0 through 4.0.0.

  • CVE-2023-49095HigNov 30, 2023
    risk 0.00cvss 8.6epss 0.01

    nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.

  • CVE-2023-48310CriNov 20, 2023
    risk 0.00cvss 9.1epss 0.01

    TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtered correctly. Nmap options are accepted. In this particular case, the option to create log files is accepted in addition to a host name (and even without). A…

  • CVE-2023-5832CriOct 30, 2023
    risk 0.00cvss 9.1epss 0.01

    Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

  • CVE-2023-42448HigOct 4, 2023
    risk 0.00cvss 8.1epss 0.01

    Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum of the UTxO at the head validator must stay unchanged as the state progresses from Open to Closed (Close transaction), but no such…

  • CVE-2023-41316MedSep 7, 2023
    risk 0.00cvss 5.5epss 0.00

    Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML…

  • CVE-2023-4435MedAug 20, 2023
    risk 0.00cvss 5.5epss 0.00

    Improper Input Validation in GitHub repository hamza417/inure prior to build88.

  • CVE-2023-40165HigAug 17, 2023
    risk 0.00cvss 7.4epss 0.00

    rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any uploaded gem version that had a platform, version number, or gem name matching `/-\d/`, permanently replacing the legitimate upload…

  • CVE-2023-3724CriJul 17, 2023
    risk 0.00cvss 9.1epss 0.01

    If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret. Using a…

  • CVE-2023-36462MedJul 6, 2023
    risk 0.00cvss 5.4epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker can craft a verified profile link using specific formatting to conceal arbitrary parts of the link, enabling it to…

  • CVE-2023-32690MedJun 1, 2023
    risk 0.00cvss 5.7epss 0.01

    libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following a successful CAPABILITIES response, a libspdm Requester stores the Responder's CTExponent into its context without validation. If the Requester sends a…

  • CVE-2023-33182NonMay 30, 2023
    risk 0.00cvss 0.0epss 0.01

    Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to…

  • CVE-2023-2942HigMay 27, 2023
    risk 0.00cvss 8.1epss 0.01

    Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2021-25748HigMay 24, 2023
    risk 0.00cvss 7.6epss 0.01

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API…

  • CVE-2023-32305HigMay 12, 2023
    risk 0.00cvss 8.8epss 0.01

    aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages missing schema qualifiers on privileged…

  • CVE-2023-28856MedApr 18, 2023
    risk 0.00cvss 5.5epss 0.01

    Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and…

  • CVE-2023-30450MedApr 8, 2023
    risk 0.00cvss 4.3epss 0.01

    rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have…

  • CVE-2023-28100CriMar 16, 2023
    risk 0.00cvss 10.0epss 0.01

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability similar to CVE-2017-5226, but using the `TIOCLINUX` ioctl command instead of `TIOCSTI`. If a Flatpak…

  • CVE-2023-28099MedMar 15, 2023
    risk 0.00cvss 5.9epss 0.01

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, if `ds_is_in_list()` is used with an invalid IP address string (`NULL` is illegal input), OpenSIPS will attempt to print a string from a random address (stack garbage),…