CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-21431 LOW
Bixby Vision < 3.7.70.17 - Unauthenticated Data Access via Improper Input Validation
CVSS 3.3
CVE-2023-21428 MEDIUM
Samsung Android TelephonyUI - Improper Input Validation
CVSS 4.0
CVE-2023-0751 MEDIUM
FreeBSD - Improper Input Validation in GELI Key File Handling
CVSS 6.5
CVE-2023-0615 MEDIUM
Linux Kernel - Memory Leak and Integer Overflow in V4L2 vivid Test Code via VIDIOC_S_DV_TIMINGS ioctl
CVSS 5.5
CVE-2023-20613 MEDIUM
Android - Local Privilege Escalation via Missing Bounds Check in ril
CVSS 6.7
CVE-2023-20612 MEDIUM
Android - Local Privilege Escalation via Missing Bounds Check in ril
CVSS 6.7
CVE-2023-20606 MEDIUM
Android - Out-of-bounds Read in apusys
CVSS 4.4
CVE-2023-24493 MEDIUM
Tenable.sc < 5.23.1 - Authenticated Formula Injection via Report Export
CVSS 5.7
CVE-2023-0284 MEDIUM
Tribe29 Checkmk <2.1.0p19, <2.0.0p32, <=1.6.0 - Info Disclosure
CVSS 6.8
CVE-2023-0229 MEDIUM
github.com/openshift/apiserver-library-go - Privilege Escalation
CVSS 6.3
CVE-2023-23560 CRITICAL
Lexmark B2236/B2338/B2442/B2546/B2650/B2865/B3340/B3442/C2240/C2325/C2326/C2425/C2535/C3224/C3326 Firmware SSRF
CVSS 9.8
CVE-2023-0434 HIGH
pyload < 0.5.0b3.dev40 - Improper Input Validation
CVSS 7.5
CVE-2023-20045 MEDIUM
Cisco Small Business RV160-260 - RCE
CVSS 4.9
CVE-2023-20026 MEDIUM
Cisco Small Business RV016-325 - Command Injection
CVSS 6.5
CVE-2023-20020 HIGH
Cisco BroadWorks 22.0-23.0.1075 Unauthenticated DoS via HTTP Request Parsing
CVSS 8.6
CVE-2023-21607 HIGH
Adobe Acrobat Reader <22.003.20282 - RCE
CVSS 7.8
CVE-2023-22734 MEDIUM
Shopware < 6.4.18.1 - Newsletter Double Opt-In Bypass
CVSS 4.3
CVE-2023-22730 MEDIUM
Shopware < 6.4.18.1 - Cart Validator Bypass via Duplicate Line Item
CVSS 5.3
CVE-2023-0299 CRITICAL
publify/publify <9.2.10 - Info Disclosure
CVSS 9.8
CVE-2023-22496 HIGH
netdata < 1.37.0 - Remote Code Execution via Crafted Registry Hostname in Streaming Alert
CVSS 8.1
CVE-2023-22470 LOW
Nextcloud Deck < 1.6.5 - Denial of Service via Database Error
CVSS 3.5
CVE-2023-21596 HIGH
Adobe InCopy <= 17.4 and 18.0 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-21588 HIGH
Adobe InDesign <= 17.4 and 18.0 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-22491 HIGH
gatsby-transformer-remark <5.25.1 and 6.0.0-6.3.2 - JavaScript Injection via gray-matter Frontmatter Processing
CVSS 8.1
CVE-2023-22952 HIGH KEV
SugarCRM unauthenticated Remote Code Execution (RCE)
CVSS 8.8
Details
Vulnerabilities 12,467
Exploit Likelihood High