CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-32305 HIGH
aiven-extras < 1.1.9 - Privilege Escalation via Unqualified Function Name Collision
CVSS 8.8
CVE-2023-25927 MEDIUM
IBM Security Verify Access 10.0.0-10.0.5 - Denial of Service via Crafted HTTP Requests
CVSS 6.5
CVE-2023-29246 HIGH
Apache OpenMeetings <7.1.0 - Privilege Escalation
CVSS 7.2
CVE-2023-29195 MEDIUM
Vitess < 16.0.2 - Denial of Service via Shard Creation with Slash Characters
CVSS 4.1
CVE-2023-29026 MEDIUM
Rockwell Automation's ArmorStart ST - XSS
CVSS 4.7
CVE-2023-32075 MEDIUM
pimcore customer_management_framework < 3.3.9 - Business Logic Error via Conditions Tab Counter
CVSS 4.3
CVE-2023-31162 MEDIUM
SEL RTAC Module Firmware r149-v0-r150-v2 - Authenticated Arbitrary File Write via Web Interface
CVSS 4.8
CVE-2023-31161 MEDIUM
SEL RTAC Web Interface - Authenticated Improper Input Validation
CVSS 5.9
CVE-2023-31149 CRITICAL
SEL RTAC Web Interface - Authenticated Remote Code Execution
CVSS 9.1
CVE-2023-31148 CRITICAL
SEL RTAC Web Interface - Authenticated Remote Code Execution
CVSS 9.1
CVE-2023-25776 MEDIUM
Intel Server System Firmware < 2.90 - Authenticated Information Disclosure via Improper Input Validation
CVSS 6.3
CVE-2023-25772 MEDIUM
Intel Retail Edge Mobile Android < 3.0.301126-RELEASE - Authenticated Denial of Service via Local Access
CVSS 5.0
CVE-2023-25175 MEDIUM
Intel Server Board BMC Firmware < 2.90 - Authenticated Information Disclosure via Improper Input Validation
CVSS 6.1
CVE-2023-22379 MEDIUM
Intel(R) Server Board BMC <2.90 - Info Disclosure
CVSS 6.7
CVE-2023-1732 MEDIUM
cloudflare/circl < 1.3.3 - Predictable Shared Secret via Insufficient Randomness Check
CVSS 5.3
CVE-2023-29335 HIGH
Microsoft Word - Security Feature Bypass via Improper Input Validation
CVSS 7.5
CVE-2023-24950 MEDIUM
Microsoft SharePoint Server - Spoofing
CVSS 6.5
CVE-2023-28200 MEDIUM
iPadOS < 15.7.4 - Kernel Memory Disclosure via Input Validation Issue
CVSS 5.5
CVE-2023-27961 MEDIUM
iPadOS < 15.7.4 - Information Exfiltration via Malicious Calendar Invitation
CVSS 5.5
CVE-2023-31039 CRITICAL
Apache bRPC < 1.5.0 - Remote Code Execution via ServerOptions pid_file Parameter
CVSS 9.8
CVE-2023-31047 CRITICAL
Django <3.2.19, <4.1.9, <4.2.1 - Auth Bypass
CVSS 9.8
CVE-2023-30434 MEDIUM
IBM Storage Scale and Elastic Storage System - Denial of Service via Kernel Panic
CVSS 6.2
CVE-2023-21504 MEDIUM
Samsung Android Shannon Baseband - Buffer Overflow in mm_Plmncoordination.c
CVSS 5.6
CVE-2023-21503 MEDIUM
Samsung Android Shannon Baseband - Buffer Overflow in mm_LteInterRatManagement.c
CVSS 5.6
CVE-2023-21502 MEDIUM
Samsung Android - Privilege Escalation via FactoryTest Debugging Commands
CVSS 5.7
Details
Vulnerabilities 12,467
Exploit Likelihood High