CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 75 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-1304 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information… | ||
| CVE-2021-1302 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information… | ||
| CVE-2021-1299 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these… | ||
| CVE-2021-1298 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these… | ||
| CVE-2021-0208 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2021 | An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of… | ||
| CVE-2020-16015 | Hig | 0.57 | 8.8 | 0.01 | Jan 8, 2021 | Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2018-25002 | Hig | 0.57 | 8.8 | 0.01 | Jan 1, 2021 | uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy. | ||
| CVE-2016-9026 | Cri | 0.57 | 9.8 | 0.01 | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in fileController.php. | ||
| CVE-2016-9025 | Cri | 0.57 | 9.8 | 0.01 | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php. | ||
| CVE-2016-9023 | Cri | 0.57 | 9.8 | 0.01 | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php. | ||
| CVE-2016-9022 | Cri | 0.57 | 9.8 | 0.01 | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in usersController.php. | ||
| CVE-2016-9021 | Cri | 0.57 | 9.8 | 0.01 | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in storeController.php. | ||
| CVE-2020-35789 | Hig | 0.57 | 8.8 | 0.03 | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user. | ||
| CVE-2020-14231 | Hig | 0.57 | 8.8 | 0.01 | Dec 22, 2020 | A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would… | ||
| CVE-2019-11781 | Hig | 0.57 | 8.8 | 0.02 | Dec 22, 2020 | Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation. | ||
| CVE-2020-27687 | Hig | 0.57 | 8.8 | 0.02 | Dec 18, 2020 | ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen. | ||
| CVE-2020-27154 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2020 | The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to… | ||
| CVE-2020-7838 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2020 | A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. This issue affects: Smilegate STOVE Client 0.0.4.72. | ||
| CVE-2020-25759 | Hig | 0.57 | 8.8 | 0.02 | Dec 15, 2020 | An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests. | ||
| CVE-2020-25757 | Hig | 0.57 | 8.8 | 0.02 | Dec 15, 2020 | A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with… |
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information…
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information…
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…
- risk 0.57cvss 8.8epss 0.01
An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of…
- risk 0.57cvss 8.8epss 0.01
Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.
- risk 0.57cvss 9.8epss 0.01
Exponent CMS before 2.6.0 has improper input validation in fileController.php.
- risk 0.57cvss 9.8epss 0.01
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
- risk 0.57cvss 9.8epss 0.01
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
- risk 0.57cvss 9.8epss 0.01
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
- risk 0.57cvss 9.8epss 0.01
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
- risk 0.57cvss 8.8epss 0.03
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would…
- risk 0.57cvss 8.8epss 0.02
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
- risk 0.57cvss 8.8epss 0.02
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
- risk 0.57cvss 8.8epss 0.01
The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to…
- risk 0.57cvss 8.8epss 0.01
A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. This issue affects: Smilegate STOVE Client 0.0.4.72.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.
- risk 0.57cvss 8.8epss 0.02
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with…