CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 71 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37415 | Hig | 0.57 | 8.8 | 0.02 | Jul 13, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: before 6.1.2. … | ||
| CVE-2023-35303 | Hig | 0.57 | 8.8 | 0.01 | Jul 11, 2023 | USB Audio Class System Driver Remote Code Execution Vulnerability | ||
| CVE-2023-35797 | Cri | 0.57 | 9.8 | 0.03 | Jul 3, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this… | ||
| CVE-2023-22886 | Hig | 0.57 | 8.8 | 0.02 | Jun 29, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain… | ||
| CVE-2021-46773 | Hig | 0.57 | 8.8 | 0.01 | May 9, 2023 | Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution. | ||
| CVE-2021-46769 | Hig | 0.57 | 8.8 | 0.01 | May 9, 2023 | Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution. | ||
| CVE-2023-31047 | Cri | 0.57 | 9.8 | 0.01 | May 7, 2023 | In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was… | ||
| CVE-2023-0896 | Hig | 0.57 | 8.8 | 0.00 | May 1, 2023 | A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access. | ||
| CVE-2023-1789 | Cri | 0.57 | 9.8 | 0.00 | Apr 1, 2023 | Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0. | ||
| CVE-2022-47192 | Hig | 0.57 | 8.8 | 0.01 | Mar 31, 2023 | Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to replace the administrator password. | ||
| CVE-2023-20960 | Hig | 0.57 | 8.8 | 0.00 | Mar 24, 2023 | In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-27586 | Cri | 0.57 | 9.9 | 0.01 | Mar 20, 2023 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or… | ||
| CVE-2023-25696 | Cri | 0.57 | 9.8 | 0.02 | Feb 24, 2023 | Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | ||
| CVE-2023-25693 | Cri | 0.57 | 9.8 | 0.02 | Feb 24, 2023 | Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. | ||
| CVE-2023-25691 | Cri | 0.57 | 9.8 | 0.02 | Feb 24, 2023 | Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | ||
| CVE-2023-21685 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2023 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-0299 | Cri | 0.57 | 9.8 | 0.01 | Jan 14, 2023 | Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. | ||
| CVE-2022-40145 | Cri | 0.57 | 9.8 | 0.02 | Dec 21, 2022 | This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName)… | ||
| CVE-2022-38123 | Hig | 0.57 | 8.7 | 0.01 | Dec 6, 2022 | Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0. | ||
| CVE-2022-36960 | Hig | 0.57 | 8.8 | 0.01 | Nov 29, 2022 | SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges. |
- risk 0.57cvss 8.8epss 0.02
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: before 6.1.2. …
- risk 0.57cvss 8.8epss 0.01
USB Audio Class System Driver Remote Code Execution Vulnerability
- risk 0.57cvss 9.8epss 0.03
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this…
- risk 0.57cvss 8.8epss 0.02
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain…
- risk 0.57cvss 8.8epss 0.01
Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution.
- risk 0.57cvss 8.8epss 0.01
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.
- risk 0.57cvss 9.8epss 0.01
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was…
- risk 0.57cvss 8.8epss 0.00
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access.
- risk 0.57cvss 9.8epss 0.00
Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.
- risk 0.57cvss 8.8epss 0.01
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to replace the administrator password.
- risk 0.57cvss 8.8epss 0.00
In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…
- risk 0.57cvss 9.9epss 0.01
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or…
- risk 0.57cvss 9.8epss 0.02
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.
- risk 0.57cvss 9.8epss 0.02
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
- risk 0.57cvss 9.8epss 0.02
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
- risk 0.57cvss 8.8epss 0.01
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 9.8epss 0.01
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
- risk 0.57cvss 9.8epss 0.02
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName)…
- risk 0.57cvss 8.7epss 0.01
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.
- risk 0.57cvss 8.8epss 0.01
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.