CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2022-28127 CRITICAL
Robustel R1510 Firmware 3.3.0 - Unauthenticated Arbitrary File Deletion via Web Server Remove API
CVSS 9.1
CVE-2022-2145 MEDIUM
Cloudflare WARP <2022.5.309.0 - Privilege Escalation
CVSS 5.8
CVE-2022-31036 MEDIUM
Argo CD 1.3.0-2.1.15 - Sensitive File Exposure via Symlink Following
CVSS 4.3
CVE-2022-26864 MEDIUM
Dell Alienware M15 R5 Firmware < 1.5.0 - Authenticated Security Control Bypass via SMI Input
CVSS 6.3
CVE-2022-26863 MEDIUM
Dell Alienware M15 R5 Firmware < 1.5.0 - Authenticated Security Control Bypass via SMI Input
CVSS 6.3
CVE-2022-26862 MEDIUM
Dell Alienware M15 R5 Firmware < 1.5.0 - Authenticated Security Control Bypass via SMI Input
CVSS 6.3
CVE-2022-32534 HIGH
Bosch PRA-ES8P2S Firmware < 1.01.05 - OS Command Injection via Diagnostics Web Interface
CVSS 8.8
CVE-2022-33754 CRITICAL
CA Automic Automation 12.2-12.3 - Remote Code Execution via Insufficient Input Validation
CVSS 9.8
CVE-2022-33752 CRITICAL
CA Automic Automation 12.2-12.3 - Remote Code Execution via Insufficient Input Validation
CVSS 9.8
CVE-2022-21180 MEDIUM
Intel Xeon E3 v5 Firmware - Authenticated Denial of Service via Improper Input Validation
CVSS 5.5
CVE-2022-32154 MEDIUM
Splunk < 9.0 - SPL Safeguard Bypass via Form Token Injection
CVSS 6.8
CVE-2022-20205 MEDIUM
Android - Local Information Disclosure via File URI Scheme Validation Bypass
CVSS 5.5
CVE-2022-20186 HIGH
Android - Local Privilege Escalation
CVSS 7.8
CVE-2022-20156 HIGH
Android Kernel GraphicBuffer - Local Privilege Escalation via unflatten Validation
CVSS 7.8
CVE-2022-20134 HIGH
Android - Local Privilege Escalation via CallSubjectDialog Phone Number Spoofing
CVSS 7.8
CVE-2022-20129 MEDIUM
Android - Local Denial of Service via Phone Account Registration
CVSS 5.5
CVE-2022-32243 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malicious SVG File
CVSS 5.5
CVE-2022-32242 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Manipulated Radiance Picture Files
CVSS 5.5
CVE-2022-32241 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malicious PDF File
CVSS 5.5
CVE-2022-32240 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malicious JT File
CVSS 5.5
CVE-2022-32239 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malformed JPEG 2000 File
CVSS 5.5
CVE-2022-32238 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malformed EPS File
CVSS 5.5
CVE-2022-32237 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malformed CGM File
CVSS 5.5
CVE-2022-32236 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malformed BMP File
CVSS 5.5
CVE-2022-32235 MEDIUM
SAP 3D Visual Enterprise Viewer < 9.0 - Denial of Service via Malicious AutoCAD File
CVSS 5.5
Details
Vulnerabilities 12,467
Exploit Likelihood High