CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-27488 MEDIUM
Envoy < 1.22.9 - Privilege Escalation via Non-UTF-8 HTTP Header in ext_authz Filter
CVSS 5.4
CVE-2023-27487 HIGH
Envoy < 1.22.9 - Unauthenticated JWT Bypass via x-envoy-original-path Header
CVSS 8.2
CVE-2023-1789 CRITICAL
firefly-iii <6.0.0 - Info Disclosure
CVSS 9.8
CVE-2023-28733 HIGH
AnyMailing Joomla Plugin <8.3.0 - XSS
CVSS 7.2
CVE-2023-28732 MEDIUM
AnyMailing Joomla Plugin <8.3.0 - Info Disclosure
CVSS 6.5
CVE-2023-28731 CRITICAL
AcyMailing Joomla Plugin < 8.3.0 - Unauthenticated File Upload Code Execution
CVSS 9.8
CVE-2023-24304 HIGH
IrfanView 4.60 - Remote Code Execution via Crafted PDF File
CVSS 7.8
CVE-2023-25901 HIGH
Adobe Dimension < 3.4.7 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-25881 HIGH
Adobe Dimension < 3.4.7 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-25879 HIGH
Adobe Dimension < 3.4.7 - Remote Code Execution via Malicious File
CVSS 7.8
CVE-2023-0775 MEDIUM
Silabs Gecko Software Development Kit - Denial of Service via Invalid Prepare Write Request
CVSS 6.5
CVE-2023-25867 HIGH
Adobe Substance 3D Stager < 2.0.0 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-25865 HIGH
Adobe Substance 3D Stager < 2.0.0 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-25661 MEDIUM
TensorFlow < 2.11.1 - Denial of Service via Convolution3DTranspose Invalid Input
CVSS 6.5
CVE-2023-20976 HIGH
Android 13 - Local Privilege Escalation via DefaultAutofillPicker Input Validation
CVSS 7.3
CVE-2023-20960 HIGH
Android - Local Privilege Escalation via SettingsHomepageActivity Deep Link Intent
CVSS 8.8
CVE-2023-28330 MEDIUM
moodle 3.9.0-3.9.19 and 4.1.0-4.1.1 - Authenticated Arbitrary File Read via Backup Feature
CVSS 6.5
CVE-2023-1289 MEDIUM
ImageMagick < 7.1.1-0 - Denial of Service via Crafted SVG File
CVSS 5.5
CVE-2023-20072 HIGH
Cisco IOS XE - Unauthenticated Denial of Service via Fragmented Tunnel Protocol Packets
CVSS 8.6
CVE-2023-25859 HIGH
Adobe Illustrator < 26.5.2 and <= 27.2.0 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-27984 HIGH
Schneider Electric Custom Reports < 16.0.0.23040 - Remote Code Execution via Malicious Report File
CVSS 7.8
CVE-2023-27586 CRITICAL
CairoSVG < 2.7.0 - Server-Side Request Forgery via External Host Requests
CVSS 9.9
CVE-2023-1250 HIGH
OTRS 6.0.1-6.0.34 and 7.0.0-7.0.41 - Local Code Execution via ACL Comment Injection
CVSS 7.4
CVE-2023-28113 MEDIUM
russh <0.36.2-0.37.1 - Info Disclosure
CVSS 5.9
CVE-2023-21453 MEDIUM
Samsung Android - Improper Input Validation in SoftSim TA
CVSS 6.0
Details
Vulnerabilities 12,467
Exploit Likelihood High