CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-32695 HIGH
socket.io-parser 3.4.0-3.4.2 and 4.0.4-4.2.2 - Denial of Service via Crafted Socket.IO Packet
CVSS 7.3
CVE-2023-32688 MEDIUM
parse-server-push-adapter < 4.1.3 - Denial of Service via Invalid Push Notification Payload
CVSS 4.9
CVE-2023-32321 CRITICAL
CKAN 2.9.0-2.9.8 - Remote Code Execution via ResourceUploader Arbitrary File Write
CVSS 9.8
CVE-2023-21516 HIGH
Samsung Galaxy Store < 4.5.49.8 - Cross-Site Scripting via InstantPlay
CVSS 7.5
CVE-2023-21515 HIGH
Samsung Galaxy Store < 4.5.49.8 - Remote Code Execution via InstantPlay JavaScript Injection
CVSS 7.5
CVE-2023-21514 HIGH
Samsung Galaxy Store < 4.5.49.8 - Arbitrary APK Installation via InstantPlay Deeplink Scheme Validation Bypass
CVSS 7.5
CVE-2023-32323 MEDIUM
Synapse <= 1.73 - Denial of Service via Oversized invite_room_state Field
CVSS 5.0
CVE-2023-2868 CRITICAL KEV
Barracuda Email Security Gateway <9.2.0.006 - Command Injection
CVSS 9.4
CVE-2023-30440 MEDIUM
IBM PowerVM Hypervisor FW860.00-FW1030.10 - DoS and Arbitrary Data Corruption via SRIOV
CVSS 6.7
CVE-2023-28649 HIGH
Snap One OvrC - Privilege Escalation
CVSS 8.6
CVE-2023-20182 MEDIUM
Cisco DNA Center - Privilege Escalation
CVSS 5.4
CVE-2023-20172 MEDIUM
Cisco Identity Services Engine - Authenticated Arbitrary File Delete and Read
CVSS 5.4
CVE-2023-20171 MEDIUM
Cisco Identity Services Engine - Authenticated Arbitrary File Delete and Read
CVSS 5.4
CVE-2023-21111 MEDIUM
Android - Local Denial of Service via PhoneAccountRegistrar Input Validation
CVSS 5.5
CVE-2023-20722 MEDIUM
Android - Local Privilege Escalation via m4u Improper Input Validation
CVSS 6.7
CVE-2023-20721 MEDIUM
Android - Local Privilege Escalation via ISP Improper Input Validation
CVSS 6.7
CVE-2023-20720 MEDIUM
Android - Out-of-Bounds Read in pqframework
CVSS 6.7
CVE-2023-20719 MEDIUM
Android - Out-of-bounds Read in pqframework
CVSS 4.4
CVE-2023-20718 MEDIUM
Android - Out-of-Bounds Write in VCU due to Missing Bounds Check
CVSS 6.7
CVE-2023-20710 MEDIUM
Android - Local Information Disclosure via Missing Bounds Check in keyinstall
CVSS 4.4
CVE-2023-20709 MEDIUM
Android - Local Information Disclosure via Missing Bounds Check in keyinstall
CVSS 4.4
CVE-2023-20708 MEDIUM
Android - Out-of-Bounds Read in Keyinstall
CVSS 6.7
CVE-2023-20707 MEDIUM
Android - Local Privilege Escalation via Missing Bounds Check in ril
CVSS 6.7
CVE-2023-20705 MEDIUM
Android - Local Information Disclosure via Missing Bounds Check in APU
CVSS 5.5
CVE-2023-20704 MEDIUM
Android - Local Information Disclosure via Missing Bounds Check in APU
CVSS 5.5
Details
Vulnerabilities 12,467
Exploit Likelihood High