CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2022-20913 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Arbitrary File Write via Web Management Interface
CVSS 4.9
CVE-2022-20909 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Privilege Escalation via CLI Command Execution
CVSS 6.0
CVE-2022-20908 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Privilege Escalation via CLI Command Injection
CVSS 6.0
CVE-2022-22214 MEDIUM
Juniper Networks Junos OS/Junos OS Evolved - DoS
CVSS 6.5
CVE-2022-34866 HIGH
Passage Drive 1.4.0-1.5.1.0 & Box 1.0.0 - Local Privilege Escalation via IPC Data Verification
CVSS 7.8
CVE-2022-35404 HIGH
ManageEngine OPManager < 12.5 - Unauthenticated Arbitrary File and Directory Creation
CVSS 8.2
CVE-2022-26655 HIGH
Pexip Infinity <27.3 - Buffer Overflow
CVSS 7.5
CVE-2022-34758 MEDIUM
Easergy P5 Firmware < 01.401.102 - Authenticated Watchdog Disablement via Improper Input Validation
CVSS 5.1
CVE-2022-35171 MEDIUM
SAP 3D Visual Enterprise Viewer - Denial of Service via Malformed JPEG 2000 File
CVSS 5.5
CVE-2022-32248 MEDIUM
SAP S/4HANA 101-106 - Improper Input Validation in Manage Checkbooks Component
CVSS 5.3
CVE-2022-2385 HIGH
aws-iam-authenticator - Privilege Escalation
CVSS 8.1
CVE-2022-33710 HIGH
Galaxy Store <4.5.41.8 - Privilege Escalation
CVSS 7.8
CVE-2022-33709 HIGH
Galaxy Store <4.5.41.8 - Privilege Escalation
CVSS 7.8
CVE-2022-33708 HIGH
Galaxy Store <4.5.41.8 - Privilege Escalation
CVSS 7.8
CVE-2022-33704 HIGH
KnoxSDK <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 8.5
CVE-2022-33703 HIGH
CACertificateInfo <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 8.5
CVE-2022-33690 MEDIUM
Contacts Storage <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2022-30756 HIGH
Finder <SMR Jul-2022 Release 1 - Privilege Escalation
CVSS 8.5
CVE-2022-30754 HIGH
AppLinker <SMR Jul-2022 Release 1 - Privilege Escalation
CVSS 8.5
CVE-2022-2047 LOW
Eclipse Jetty 9.4.0-9.4.46, 10.0.0-10.0.9, 11.0.0-11.0.9 - Improper Input Validation in HttpURI Authority Parsing
CVSS 2.7
CVE-2022-31121 HIGH
Hyperledger Fabric <2.2.7, <2.4.5 - DoS
CVSS 7.5
CVE-2022-29892 MEDIUM
Cybozu Garoon 4.0.0-5.5.1 - Authenticated Denial of Service via Space Input Validation
CVSS 6.5
CVE-2022-28692 MEDIUM
Cybozu Garoon <5.5.1 - Info Disclosure
CVSS 4.3
CVE-2022-27807 MEDIUM
Cybozu Garoon 4.0.0-5.5.1 - Authenticated Denial of Service via Category Addition Disruption
CVSS 4.3
CVE-2022-27803 MEDIUM
Cybozu Garoon 4.0.0-5.5.1 - Authenticated Data Manipulation via Space Input Validation
CVSS 4.3
Details
Vulnerabilities 12,467
Exploit Likelihood High