CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-36888 MEDIUM
Microsoft Edge Chromium < 114.0.1823.82 - Tampering
CVSS 6.3
CVE-2023-3434 MEDIUM
Jami 20222284 - Denial of Service via Hyperlink Interpretation
CVSS 4.4
CVE-2023-3433 MEDIUM
Jami - Local Denial of Service via Nickname Field Special Character Injection
CVSS 5.5
CVE-2023-30559 MEDIUM
BD Alaris 8015 PCU Firmware < 12.1.3 - Unauthenticated Firmware Update Package Tampering
CVSS 5.2
CVE-2023-29457 MEDIUM
Zabbix Frontend 4.0.0-4.0.44 - Reflected Cross-Site Scripting via Action Form Fields
CVSS 6.3
CVE-2023-29456 MEDIUM
Zabbix Frontend 4.0.0-4.0.45 - Improper Input Validation in URL Validation Scheme
CVSS 5.7
CVE-2023-29455 MEDIUM
Zabbix Frontend 4.0.0-4.0.44 - Reflected Cross-Site Scripting
CVSS 5.4
CVE-2023-29454 MEDIUM
Zabbix Frontend 4.0.0-4.0.44 - Stored Cross-Site Scripting
CVSS 5.4
CVE-2023-29452 MEDIUM
Zabbix 6.0.0-6.0.16 - Stored Cross-Site Scripting in Geomap Attribution Text
CVSS 5.5
CVE-2023-29451 MEDIUM
Zabbix - Denial of Service via JSON Parser Buffer Overrun
CVSS 4.7
CVE-2023-37415 HIGH
Apache Airflow Apache Hive Provider < 6.1.2 - OS Command Injection via Proxy User Option
CVSS 8.8
CVE-2023-21251 HIGH
Android - Local Privilege Escalation via ConfirmDialog Input Validation Bypass
CVSS 7.3
CVE-2023-37948 LOW
Jenkins Oracle Cloud Infrastructure Compute Plugin < 1.0.17 - Man-in-the-Middle via Unvalidated SSH Host Keys
CVSS 3.7
CVE-2023-22888 MEDIUM
Apache Airflow < 2.6.3 - Authenticated Denial of Service via run_id Parameter
CVSS 6.5
CVE-2023-36872 MEDIUM
VP9 Video Extensions - Info Disclosure
CVSS 5.5
CVE-2023-35367 CRITICAL
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 9.8
CVE-2023-35366 CRITICAL
Windows RRAS - Remote Code Execution via Improper Input Validation
CVSS 9.8
CVE-2023-35365 CRITICAL
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 9.8
CVE-2023-35336 MEDIUM
Windows 10 1507-22H2, Windows 11 21H2-22H2, Windows Server 2012-2022 - Security Feature Bypass in MSHTML Platform
CVSS 6.5
CVE-2023-35306 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure via PostScript and PCL6 Printer Driver
CVSS 5.5
CVE-2023-35303 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution in USB Audio Class System Driver
CVSS 8.8
CVE-2023-32057 CRITICAL
Microsoft Windows MSMQ - Remote Code Execution via Improper Input Validation
CVSS 9.8
CVE-2023-32037 MEDIUM
Windows Layer-2 Bridge - Info Disclosure
CVSS 6.5
CVE-2023-22835 HIGH
Palantir Foundry Issues < 2.510.0 and Foundry Frontend < 6.228.0 - Denial of Service via Malformed Issue Data
CVSS 7.7
CVE-2023-30449 HIGH
IBM Db2 10.5, 11.1, 11.5 - Denial of Service via Crafted Query
CVSS 7.5
Details
Vulnerabilities 12,467
Exploit Likelihood High