CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-21501 HIGH
Samsung Android mPOS Fiserve Trustlet - Remote Code Execution
CVSS 8.2
CVE-2023-21498 MEDIUM
Samsung Android - Memory Overwrite via mPOS TUI Trustlet setPartnerTAInfo
CVSS 6.0
CVE-2023-21494 MEDIUM
Samsung Android Shannon Baseband - Buffer Overflow in mm_Authentication.c
CVSS 5.6
CVE-2023-26125 MEDIUM
Gin-Gonic Gin <1.9.0 - Improper Input Validation
CVSS 5.6
CVE-2023-0683 HIGH
Lenovo ThinkAgile HX Series Firmware - Authenticated Privilege Escalation via Crafted API Call
CVSS 8.3
CVE-2023-0896 HIGH
Lenovo Smart Clock Essential with Alexa Built In Firmware < 90 - Unauthenticated Default Password Bypass
CVSS 8.8
CVE-2023-26022 MEDIUM
IBM Db2 11.1-11.1.4 - Denial of Service via DBMS_OUTPUT Module
CVSS 5.9
CVE-2023-26021 HIGH
IBM Db2 11.1-11.5 - Denial of Service via LIMIT Clause
CVSS 7.5
CVE-2023-27555 MEDIUM
IBM Db2 11.5 - Denial of Service via ACR Client Affinity for Unfenced DRDA Federation Wrappers
CVSS 5.1
CVE-2023-25930 MEDIUM
IBM Db2 10.1, 11.1, 11.5 - Denial of Service via Special Register Setting
CVSS 5.9
CVE-2023-29255 HIGH
IBM DB2 10.5, 11.1, 11.5 - Denial of Service via Anonymous Block Compilation
CVSS 7.5
CVE-2023-27559 MEDIUM
IBM Db2 10.5, 11.1, 11.5 - Denial of Service via Crafted Subquery
CVSS 5.3
CVE-2023-30269 HIGH
cltphp <=6.0 - Improper Input Validation in Template Controller
CVSS 8.1
CVE-2023-29530 HIGH
Laminas Diactoros < 2.18.1 - Denial of Service via Newline in HTTP Header
CVSS 7.5
CVE-2023-29780 HIGH
Third Reality Smart Blind 1.00.54 - Denial of Service via Malicious Zigbee Messages
CVSS 7.5
CVE-2023-22916 HIGH
Zyxel USG FLEX/ATP/VPN Series Firmware 5.00-5.35 - DoS via Configuration Parser Input Sanitization Bypass
CVSS 8.1
CVE-2023-22581 CRITICAL
White Rabbit Switch < 6.0.1 - OS Command Injection
CVSS 9.8
CVE-2023-21092 HIGH
Android - Local Privilege Escalation via BroadcastReceiver Registration
CVSS 7.8
CVE-2023-27043 MEDIUM
Python <3.11.3 - Info Disclosure
CVSS 5.3
CVE-2023-29410 HIGH
Schneider Electric InsightHome, InsightFacility, Conext Gateway Firmware < 1.16 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2023-28856 MEDIUM
Redis < 6.0.19 - Authenticated Denial of Service via HINCRBYFLOAT Command
CVSS 5.5
CVE-2023-28981 MEDIUM
Juniper Networks Junos OS <20.3R3-S5, <20.4R3-S3, <21.1 - DoS
CVSS 6.5
CVE-2023-30542 MEDIUM
OpenZeppelin Contracts 4.3.0-4.8.2 - Improper Input Validation in GovernorCompatibilityBravo Proposal Creation
CVSS 6.8
CVE-2023-30535 HIGH
Snowflake JDBC < 3.13.29 - Remote Code Execution via Malicious SSO URL
CVSS 7.3
CVE-2023-29194 MEDIUM
Vitess < 16.0.1 - Denial of Service via Keyspace Name with Forward Slash
CVSS 4.1
Details
Vulnerabilities 12,467
Exploit Likelihood High