VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 70 of 668
  • CVE-2024-2746HigMay 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary configuration parameters from unprivileged users, which allowed a local root exploit by tricking the daemon into loading a user controlled "plugin". All of this…

  • CVE-2024-28976HigApr 24, 2024
    risk 0.57cvss 8.8epss 0.00

    Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the…

  • CVE-2024-26164HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-23717HigMar 11, 2024
    risk 0.57cvss 8.8epss 0.00

    In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2024-21625HigJan 4, 2024
    risk 0.57cvss 8.8epss 0.01

    SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to trigger actions in the application from its web contents. Because, prior to version 0.10.35, the deep link URLs…

  • CVE-2023-47804HigDec 29, 2023
    risk 0.57cvss 8.8epss 0.03

    Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. …

  • CVE-2023-48693HigDec 5, 2023
    risk 0.57cvss 8.7epss 0.01

    Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arbitrary read and write due to vulnerability in parameter checking mechanism in Azure RTOS ThreadX, which may lead to privilege…

  • CVE-2023-47107HigNov 8, 2023
    risk 0.57cvss 8.8epss 0.01

    PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL…

  • CVE-2023-40061HigNov 1, 2023
    risk 0.57cvss 8.8epss 0.00

     Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.

  • CVE-2022-4886HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.02

    Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

  • CVE-2023-38218HigOct 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and privilege escalation.

  • CVE-2023-20231HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending…

  • CVE-2023-39357HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not…

  • CVE-2023-40743CriSep 5, 2023
    risk 0.57cvss 9.8epss 0.03

    ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API…

  • CVE-2023-40798HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40797HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40801HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn

  • CVE-2023-40800HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.

  • CVE-2023-35368HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft Exchange Remote Code Execution Vulnerability

  • CVE-2023-39532CriAug 8, 2023
    risk 0.57cvss 9.8epss 0.01

    SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior to 0.14.5, an 0.13.0 prior to 0.13.5, there is a hole in the…