CWE-233
Improper Handling of Parameters
Description
The product does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-39
CVEs mapped to this weakness (35)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32261 | Med | 0.35 | 5.3 | 0.01 | Jun 14, 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a misconfiguration in the APT update. This could allow an attacker to add insecure packages to the application. | ||
| CVE-2023-28898 | Med | 0.34 | 5.3 | 0.00 | Jan 12, 2024 | The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows an attacker connected to the in-vehicle Wi-Fi network to cause denial-of-service of the infotainment… | ||
| CVE-2023-50727 | Med | 0.34 | 6.3 | 0.01 | Dec 22, 2023 | Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. Reflected XSS issue occurs when /queues is appended with /"><svg%20onload=alert(domain)>. This issue has been patched in version 2.6.0. | ||
| CVE-2023-50725 | Med | 0.34 | 6.3 | 0.01 | Dec 22, 2023 | Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. The following paths in resque-web have been found to be vulnerable to reflected XSS: "/failed/?class=" and… | ||
| CVE-2023-50724 | Med | 0.34 | 6.3 | 0.00 | Dec 21, 2023 | Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path… | ||
| CVE-2024-9329 | Med | 0.33 | 6.1 | 0.01 | Sep 30, 2024 | In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a… | ||
| CVE-2026-22626 | Med | 0.32 | 4.9 | 0.00 | Jan 30, 2026 | Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can cause abnormal device behavior by crafting specific messages. | ||
| CVE-2023-1419 | Med | 0.31 | 5.9 | 0.00 | Nov 17, 2024 | A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may allow the viewing of unauthorized data. | ||
| CVE-2024-33433 | Med | 0.31 | 4.8 | 0.01 | May 14, 2024 | Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page. | ||
| CVE-2020-10069 | Med | 0.28 | 4.3 | 0.00 | May 25, 2021 | Zephyr Bluetooth unchecked packet data results in denial of service. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Parameters (CWE-233). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-f6vh-7v4x-8fjp | ||
| CVE-2024-25979 | Med | 0.27 | 5.3 | 0.01 | Feb 19, 2024 | The URL parameters accepted by forum search were not limited to the allowed parameters. | ||
| CVE-2026-33585 | Low | 0.25 | 3.8 | 0.00 | May 13, 2026 | Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03. | ||
| CVE-2026-0515 | Med | 0.00 | 6.2 | 0.00 | Jul 14, 2026 | Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel. | ||
| CVE-2022-45182 | Cri | 0.00 | 9.8 | 0.01 | Nov 11, 2022 | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter. | ||
| CVE-2021-28675 | Med | 0.00 | 5.5 | 0.01 | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Image.open prior to Image.load. |
- risk 0.35cvss 5.3epss 0.01
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a misconfiguration in the APT update. This could allow an attacker to add insecure packages to the application.
- risk 0.34cvss 5.3epss 0.00
The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows an attacker connected to the in-vehicle Wi-Fi network to cause denial-of-service of the infotainment…
- risk 0.34cvss 6.3epss 0.01
Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. Reflected XSS issue occurs when /queues is appended with /"><svg%20onload=alert(domain)>. This issue has been patched in version 2.6.0.
- risk 0.34cvss 6.3epss 0.01
Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. The following paths in resque-web have been found to be vulnerable to reflected XSS: "/failed/?class=" and…
- risk 0.34cvss 6.3epss 0.00
Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path…
- risk 0.33cvss 6.1epss 0.01
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a…
- risk 0.32cvss 4.9epss 0.00
Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can cause abnormal device behavior by crafting specific messages.
- risk 0.31cvss 5.9epss 0.00
A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may allow the viewing of unauthorized data.
- risk 0.31cvss 4.8epss 0.01
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
- risk 0.28cvss 4.3epss 0.00
Zephyr Bluetooth unchecked packet data results in denial of service. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Parameters (CWE-233). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-f6vh-7v4x-8fjp
- risk 0.27cvss 5.3epss 0.01
The URL parameters accepted by forum search were not limited to the allowed parameters.
- risk 0.25cvss 3.8epss 0.00
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
- risk 0.00cvss 6.2epss 0.00
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
- risk 0.00cvss 9.8epss 0.01
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Image.open prior to Image.load.