CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-28100 CRITICAL
flatpak < 1.10.8 - Command Injection via TIOCLINUX ioctl
CVSS 10.0
CVE-2023-24571 HIGH
Dell Embedded Box PC 3000 Firmware < 1.18.0 - Authenticated Arbitrary Code Execution
CVSS 7.5
CVE-2023-28099 MEDIUM
OpenSIPS < 3.1.9 - Denial of Service via ds_is_in_list() Invalid IP Address Handling
CVSS 5.9
CVE-2023-28098 MEDIUM
OpenSIPS < 3.1.7 - Denial of Service via Crafted Authorization Header
CVSS 5.9
CVE-2023-28095 HIGH
OpenSIPS < 3.1.7 - Denial of Service via build_res_buf_from_sip_req Function
CVSS 7.5
CVE-2023-27601 HIGH
OpenSIPS < 3.1.7 - Denial of Service via Malformed SDP Body in sipmsgops Module
CVSS 7.5
CVE-2023-27600 HIGH
OpenSIPS < 3.1.7 - Denial of Service via Malformed SDP Body in sipmsgops Module
CVSS 7.5
CVE-2023-27599 HIGH
OpenSIPS < 3.1.7 - Denial of Service via Malformed To Header in append_hf Function
CVSS 7.5
CVE-2023-27597 HIGH
OpenSIPS < 3.1.8 - Denial of Service via Crafted SIP Message in rewrite_ruri Function
CVSS 7.5
CVE-2023-0100 HIGH
Eclipse BIRT 2.6.2-4.13.0 - Server-Side Request Forgery via Report Parameter
CVSS 8.8
CVE-2023-24866 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
CVE-2023-24865 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
CVE-2023-24856 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 7.5
CVE-2023-23419 HIGH
Windows 11 22H2 < 10.0.22000.1413 - Elevation of Privilege in ReFS
CVSS 7.8
CVE-2023-23416 HIGH
Windows Cryptographic Services - Remote Code Execution
CVSS 7.8
CVE-2023-23409 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure in Client Server Run-Time Subsystem
CVSS 5.5
CVE-2023-23397 CRITICAL KEV
Microsoft Outlook - Privilege Escalation
CVSS 9.8
CVE-2023-24579 MEDIUM
McAfee Total Protection <16.0.51 - Info Disclosure
CVSS 5.5
CVE-2023-24033 HIGH
Samsung Exynos Modem 5123, 5300, 980, 1080, and Auto T5123 Firmware - Denial of Service via SDP Format Type Mismatch
CVSS 7.5
CVE-2023-24975 MEDIUM
IBM Spectrum Symphony 7.3 - HTTP Header Injection via HOST Header
CVSS 5.4
CVE-2023-25947 MEDIUM
OpenHarmony 3.1-3.1.4 - Denial of Service via Malicious HAP Package Installation
CVSS 6.2
CVE-2023-24465 MEDIUM
OpenHarmony - Null Pointer Reference
CVSS 5.5
CVE-2023-22301 MEDIUM
OpenHarmony <v3.1.5 - Memory Corruption
CVSS 6.5
CVE-2023-27484 MEDIUM
crossplane 1.9.0-1.9.1 - Uncontrolled Resource Consumption via High Index in Composition Patch
CVSS 6.2
CVE-2023-27483 MEDIUM
crossplane-runtime 0.17.0-0.19.1 - Uncontrolled Resource Consumption via Paved.SetValue Method
CVSS 5.9
Details
Vulnerabilities 12,467
Exploit Likelihood High