CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2022-3736 HIGH
BIND 9.16.12-9.16.36 9.18.0-9.18.10 9.19.0-9.19.8 9.16.12-S1-9.16.36-S1 - Denial of Service via RRSIG Query
CVSS 7.5
CVE-2022-41733 MEDIUM
IBM InfoSphere Information Server 11.7 - DoS
CVSS 5.3
CVE-2022-47966 CRITICAL KEV
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
CVSS 9.8
CVE-2022-34436 LOW
Dell iDRAC8 < 2.84.84.84 - Authenticated Firmware Lock-Down Bypass via Racadm
CVSS 2.7
CVE-2022-34435 LOW
Dell iDRAC9 < 6.00.30.00 - Authenticated Firmware Lock-Down Bypass via Racadm
CVSS 2.7
CVE-2022-34460 HIGH
Dell Inspiron and G5 SE Firmware - Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2022-34393 HIGH
Dell G5 SE 5505 Firmware < 1.12.1 - Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2022-32490 HIGH
Dell Edge Gateway 3000 Firmware < 1.9.0 - Authenticated Arbitrary Code Execution via SMI
CVSS 7.5
CVE-2022-47917 MEDIUM
Sewio RTLS Studio 2.0.0-2.6.2 - Arbitrary File Deletion & DoS via Input Validation
CVSS 6.8
CVE-2022-43455 MEDIUM
Sewio's RTLS Studio <2.6.2 - Privilege Escalation
CVSS 5.5
CVE-2022-41861 MEDIUM
FreeRADIUS < 3.0.25 - Denial of Service via Malformed Abinary Attribute
CVSS 6.5
CVE-2022-46372 HIGH
Alotcer AR7088H-A <16.10.3 - Command Injection
CVSS 7.2
CVE-2022-4428 HIGH
Cloudflare WARP < 2022.10.106.0 - Privilege Escalation via Unvalidated Support URI in MDM Config
CVSS 8.9
CVE-2022-23814 MEDIUM
AMD MilanPI-SP3 Firmware <= 1.0.0.9 - Memory Corruption
CVSS 5.3
CVE-2022-33300 HIGH
Automotive Android OS - Memory Corruption
CVSS 8.4
CVE-2022-23549 MEDIUM
Discourse < 2.8.14 - Input Validation Bypass via HTML Comments
CVSS 5.7
CVE-2022-45875 CRITICAL
Apache DolphinScheduler < 3.0.2 - Authenticated Remote Code Execution via Script Alert Plugin
CVSS 9.8
CVE-2022-32653 MEDIUM
Android - Use-After-Free in mtk-aie
CVSS 6.7
CVE-2022-32652 MEDIUM
Android - Use-After-Free in mtk-aie
CVSS 6.7
CVE-2022-42269 HIGH
NVIDIA Jetson Linux < 32.7.2 - Information Disclosure and Integrity Compromise via SMC Call Handler
CVSS 7.9
CVE-2022-34681 MEDIUM
NVIDIA GPU Display Driver for Windows - Denial of Service via Improper Input Validation in Kernel Mode Layer
CVSS 5.5
CVE-2022-39012 HIGH
Huawei Aslan Children's Watch - Info Disclosure
CVSS 7.5
CVE-2022-43849 MEDIUM
IBM AIX 7.1-7.3 and VIOS 3.1 - Denial of Service via pfcdd Kernel Extension
CVSS 6.2
CVE-2022-43848 MEDIUM
IBM AIX 7.1-7.3 and VIOS 3.1 - Denial of Service via perfstat Kernel Extension
CVSS 6.2
CVE-2022-40233 MEDIUM
IBM AIX 7.1-7.3 and VIOS 3.1 - Denial of Service via TCP/IP Kernel Extension
CVSS 6.2
Details
Vulnerabilities 12,467
Exploit Likelihood High