VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 75 of 668
  • CVE-2021-1304HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information…

  • CVE-2021-1302HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information…

  • CVE-2021-1299HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…

  • CVE-2021-1298HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…

  • CVE-2021-0208HigJan 15, 2021
    risk 0.57cvss 8.8epss 0.01

    An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of…

  • CVE-2020-16015HigJan 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-25002HigJan 1, 2021
    risk 0.57cvss 8.8epss 0.01

    uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.

  • CVE-2016-9026CriDec 31, 2020
    risk 0.57cvss 9.8epss 0.01

    Exponent CMS before 2.6.0 has improper input validation in fileController.php.

  • CVE-2016-9025CriDec 31, 2020
    risk 0.57cvss 9.8epss 0.01

    Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.

  • CVE-2016-9023CriDec 31, 2020
    risk 0.57cvss 9.8epss 0.01

    Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.

  • CVE-2016-9022CriDec 31, 2020
    risk 0.57cvss 9.8epss 0.01

    Exponent CMS before 2.6.0 has improper input validation in usersController.php.

  • CVE-2016-9021CriDec 31, 2020
    risk 0.57cvss 9.8epss 0.01

    Exponent CMS before 2.6.0 has improper input validation in storeController.php.

  • CVE-2020-35789HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.03

    NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

  • CVE-2020-14231HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would…

  • CVE-2019-11781HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.02

    Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.

  • CVE-2020-27687HigDec 18, 2020
    risk 0.57cvss 8.8epss 0.02

    ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.

  • CVE-2020-27154HigDec 18, 2020
    risk 0.57cvss 8.8epss 0.01

    The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to…

  • CVE-2020-7838HigDec 18, 2020
    risk 0.57cvss 8.8epss 0.01

    A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. This issue affects: Smilegate STOVE Client 0.0.4.72.

  • CVE-2020-25759HigDec 15, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.

  • CVE-2020-25757HigDec 15, 2020
    risk 0.57cvss 8.8epss 0.02

    A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with…