VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 98 of 668
  • CVE-2025-2296HigDec 9, 2025
    risk 0.55cvss epss 0.01

    EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting…

  • CVE-2025-52451HigAug 22, 2025
    risk 0.55cvss 8.5epss 0.00

    Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

  • CVE-2025-20148HigAug 14, 2025
    risk 0.55cvss 8.5epss 0.00

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability is due to improper validation of…

  • CVE-2025-5455HigJun 2, 2025
    risk 0.55cvss epss 0.00

    An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a…

  • CVE-2025-24255HigMar 31, 2025
    risk 0.55cvss 8.4epss 0.00

    A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.

  • CVE-2024-58044HigMar 4, 2025
    risk 0.55cvss 8.4epss 0.00

    Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-56135HigFeb 5, 2025
    risk 0.55cvss 8.4epss 0.01

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2024-56134HigFeb 5, 2025
    risk 0.55cvss 8.4epss 0.01

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2024-56133HigFeb 5, 2025
    risk 0.55cvss 8.4epss 0.01

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2024-56132HigFeb 5, 2025
    risk 0.55cvss 8.4epss 0.06

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2024-56131HigFeb 5, 2025
    risk 0.55cvss 8.4epss 0.06

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2017-15832HigNov 26, 2024
    risk 0.55cvss 8.4epss 0.00

    Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

  • CVE-2024-10944HigNov 12, 2024
    risk 0.55cvss 8.4epss 0.01

    A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permissions and exists due to improper input validation resulting in the possibility of a malicious Updated Agent being deployed.

  • CVE-2024-8755HigOct 11, 2024
    risk 0.55cvss 8.4epss 0.01

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2024-33065HigOct 7, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while taking snapshot when an offset variable is set by camera driver.

  • CVE-2024-6658HigSep 12, 2024
    risk 0.55cvss 8.4epss 0.01

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive)    From 7.2.49.0 to 7.2.54.11…

  • CVE-2024-38194HigSep 10, 2024
    risk 0.55cvss 8.4epss 0.01

    An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.

  • CVE-2024-31959HigJun 7, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.

  • CVE-2024-27894HigMar 12, 2024
    risk 0.55cvss 8.5epss 0.02

    The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using this method, the…

  • CVE-2024-25999HigMar 12, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.