CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,440 vulnerabilities with CWE-20
CVE-2025-69278 HIGH
Android - Remote Denial of Service via Improper Input Validation in NR Modem
CVSS 7.5
CVE-2025-61616 HIGH
Android - Remote Denial of Service via NR Modem Improper Input Validation
CVSS 7.5
CVE-2025-61615 HIGH
Android - Remote Denial of Service via Improper Input Validation in NR Modem
CVSS 7.5
CVE-2025-61614 HIGH
Android - Remote Denial of Service via Improper Input Validation in NR Modem
CVSS 7.5
CVE-2025-61613 HIGH
Android - Remote Denial of Service via Improper Input Validation in NR Modem
CVSS 7.5
CVE-2025-61612 HIGH
Android - Remote Denial of Service via Improper Input Validation in NR Modem
CVSS 7.5
CVE-2025-61611 HIGH
Modem - Denial of Service
CVSS 7.5
CVE-2025-7375 MEDIUM
Omada EAP610 Firmware < 1.6.0 - Denial of Service via Crafted HTTP Requests
CVSS 6.5
CVE-2025-11143 LOW
Jetty HTTP 9.4.0-9.4.57 - URI Parsing Bypass via Differential Interpretation
CVSS 3.7
CVE-2025-41257 MEDIUM
Suprema BioStar 2 2.9.11.6 - Auth Bypass
CVSS 4.8
CVE-2025-62816 MEDIUM
Samsung Exynos 1280/1380/1480/1580/2200/2400/2500 Firmware DoS via Unvalidated VS4L_VERTEXIOC_BOOTUP Input
CVSS 5.5
CVE-2025-48644 MEDIUM
Android - Denial of Service via Improper Input Validation
CVSS 5.5
CVE-2025-48587 MEDIUM
Android - Local Denial of Service via ProfilingService Input Validation
CVSS 6.2
CVE-2025-48585 MEDIUM
Android - Denial of Service in ProfilingService.java
CVSS 6.2
CVE-2025-14963 HIGH
Trellix HX Agent - Privilege Escalation
CVSS 7.8
CVE-2025-69251 MEDIUM
free5gc UDM <=1.4.1 - Info Disclosure
CVSS 5.3
CVE-2025-69250 HIGH
free5gc UDM <=1.4.1 - Info Disclosure
CVSS 7.5
CVE-2025-69232 HIGH
free5GC go-upf <= 1.2.6 and smf <= 1.4.0 - Denial of Service via Malformed PFCP Association Setup Request
CVSS 7.5
CVE-2025-13587 MEDIUM
WordPress 2FA Email Plugin <=1.9.8 - Auth Bypass
CVSS 6.5
CVE-2025-66614 CRITICAL
Apache Tomcat 11.0.0-M1-11.0.14 - DoS
CVSS 9.1
CVE-2025-70123 HIGH
free5gc v4.0.1 - Denial of Service via Malformed PFCP Association Setup Request
CVSS 7.5
CVE-2025-25210 HIGH
Ring 3: User Applications <16.0.12 - Privilege Escalation
CVSS 8.2
CVE-2025-22453 HIGH
Ring 3: User Applications <16.0.12 - Privilege Escalation
CVSS 7.5
CVE-2025-15566 HIGH
Kubernetes ingress-nginx auth-proxy-set-headers - Controller Code Execution
CVSS 8.8
CVE-2025-12131 MEDIUM
Silabs Simplicity Software Development Kit < 2025.6.2 - Denial of Service via Truncated 802.15.4 Packet
CVSS 6.5
Details
Vulnerabilities 12,440
Exploit Likelihood High