CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2022-45872 CRITICAL
iTerm2 < 3.4.18 - Improper Input Validation via DECRQSS Response
CVSS 9.8
CVE-2022-41942 HIGH
Sourcegraph < 4.1.0 - OS Command Injection via Gitserver /list-gitolite Host Parameter
CVSS 7.9
CVE-2022-3388 HIGH
Hitachi Energy MicroSCADA SYS600 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2022-45470 HIGH
Apache Hama < 1.7.1 - Path Traversal and Cross-Site Scripting
CVSS 7.5
CVE-2022-31616 MEDIUM
NVIDIA GPU Display Driver - Memory Corruption
CVSS 6.1
CVE-2022-31607 HIGH
NVIDIA GPU Display Driver - Memory Corruption
CVSS 7.8
CVE-2022-41909 MEDIUM
TensorFlow < 2.8.4 - NULL Pointer Dereference in CompositeTensorVariantToComponents
CVSS 4.8
CVE-2022-41908 MEDIUM
TensorFlow < 2.8.4 - Denial of Service via Non-UTF-8 Token in PyFunc
CVSS 4.8
CVE-2022-41901 MEDIUM
TensorFlow < 2.8.4 - Reachable Assertion in SparseMatrixNNZ
CVSS 4.8
CVE-2022-41899 MEDIUM
TensorFlow < 2.8.4 - Reachable Assertion in SdcaOptimizer
CVSS 4.8
CVE-2022-41898 MEDIUM
TensorFlow < 2.8.4 - Denial of Service via SparseFillEmptyRowsGrad Empty Input
CVSS 4.8
CVE-2022-41896 MEDIUM
TensorFlow < 2.8.4 - Denial of Service via ThreadUnsafeUnigramCandidateSampler Input Validation
CVSS 4.8
CVE-2022-41891 MEDIUM
TensorFlow < 2.8.4 - Denial of Service via TensorListConcat Element Shape Handling
CVSS 4.8
CVE-2022-41888 MEDIUM
TensorFlow < 2.8.4 - Denial of Service via Invalid Scores Input in generate_bounding_box_proposals
CVSS 4.8
CVE-2022-24037 HIGH
Karmasis Informatics Infraskope SIEM+ - Info Disclosure
CVSS 8.2
CVE-2022-36784 CRITICAL
Elsight Halo Firmware - Remote Code Execution via DESTINATION Parameter
CVSS 9.8
CVE-2022-20459 MEDIUM
Android kernel - Local Privilege Escalation
CVSS 6.7
CVE-2022-39389 HIGH
Btcd < 0.23.3 - Improper Input Validation
CVSS 8.2
CVE-2022-39318 MEDIUM
FreeRDP < 2.9.0 - Denial of Service via urbdrc Channel Input Validation
CVSS 4.8
CVE-2022-38385 HIGH
IBM Cloud Pak for Security <1.10.2.0 - Info Disclosure
CVSS 7.1
CVE-2022-20924 HIGH
Cisco Adaptive Security Appliance Software - Authenticated Denial of Service via SNMP Request
CVSS 7.7
CVE-2022-40773 HIGH
ManageEngine ServiceDesk Plus MSP < 10609 & SupportCenter Plus < 11025 - Privilege Escalation via ExportMickeyList
CVSS 8.8
CVE-2022-31772 MEDIUM
IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, 9.2 LTS - Authenticated Denial of Service via MQTT Channels
CVSS 5.3
CVE-2022-38099 HIGH
Intel(R) NUC 11 Compute Elements <EBTGL357.0065 - Privilege Escalation
CVSS 7.5
CVE-2022-34152 HIGH
Intel NUC <TY0070 - Privilege Escalation
CVSS 7.7
Details
Vulnerabilities 12,467
Exploit Likelihood High