CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2023-32170 MEDIUM
Unified Automation UaGateway < 1.5.13.487 - Denial of Service via Client Certificate Processing
CVSS 6.5
CVE-2023-38293 HIGH
Nokia C200/C100 - Command Injection
CVSS 7.3
CVE-2023-5397 HIGH
Honeywell Experion Server - Remote Code Execution via Malformed Connection Message
CVSS 8.1
CVE-2023-36505 MEDIUM
Ninja Forms Contact Form <3.6.24 - Info Disclosure
CVSS 6.8
CVE-2023-52385 MEDIUM
Huawei EMUI and HarmonyOS - Out-of-bounds Write in RSMC Module
CVSS 6.2
CVE-2023-52552 HIGH
Huawei EMUI - Denial of Service via Power Module Input Verification
CVSS 7.5
CVE-2023-52535 MEDIUM
Android - Denial of Service via VSP Driver Input Validation
CVSS 4.4
CVE-2023-31028 LOW
NVIDIA nvJPEG2000 Library < 0.7.x - Partial Denial of Service via Crafted Input File
CVSS 2.8
CVE-2023-52296 MEDIUM
IBM DB2 11.5 - Denial of Service via Concurrent UDF Query
CVSS 5.3
CVE-2023-33100 HIGH
Qualcomm AR8035 Firmware - Denial of Service via DL NAS Transport Message
CVSS 7.5
CVE-2023-33099 HIGH
Qualcomm Modem Firmware - NR DL NAS SMS Container Denial of Service
CVSS 7.5
CVE-2023-29134 HIGH
MediaWiki Cargo Extension <= 1.39.3 - Improper Input Validation via Backtick Handling
CVSS 8.6
CVE-2023-46047 HIGH
sane_backends 1.2.1 - Local Arbitrary Code Execution via sanei_configure_attach()
CVSS 7.3
CVE-2023-45177 MEDIUM
IBM MQ 9.0.0.0-9.0.0.20 and 9.3.0-9.3.3 - Denial of Service in Clustering Logic
CVSS 5.3
CVE-2023-51444 HIGH
GeoServer < 2.23.4, 2.24.1 - Authenticated Arbitrary File Upload and Remote Code Execution via REST Coverage Store API
CVSS 7.2
CVE-2023-7248 MEDIUM
OpenText Vertica Management Console 10.x-11.1.1-24 12.0.4-18 - Authentication Bypass via Crafted Requests
CVSS 5.0
CVE-2023-7060 HIGH
Zephyr < 3.6.0 - Improper Input Validation in IP Packet Handling
CVSS 8.6
CVE-2023-32633 MEDIUM
Intel(R) CSME <2328.5.5.0 - Privilege Escalation
CVSS 6.7
CVE-2023-42661 HIGH
JFrog Artifactory < 7.76.2 - Authenticated Arbitrary File Write via Insufficient Artifact Validation
CVSS 7.2
CVE-2023-33104 HIGH
Qualcomm Modem and FastConnect Firmware - Denial of Service via PDU Release Command
CVSS 7.5
CVE-2023-33103 HIGH
Qualcomm AR8035 Firmware - Denial of Service via CAG Info IE Processing
CVSS 7.5
CVE-2023-28578 CRITICAL
Qualcomm 315 5G IoT Modem Firmware - Memory Corruption in Core Services via Event Listener Removal
CVSS 9.3
CVE-2023-44345 MEDIUM
Adobe InDesign < 17.4.2 - Unauthenticated Denial of Service via Malicious File
CVSS 5.5
CVE-2023-50737 CRITICAL
Lexmark Printers - Arbitrary Code Execution via SE Menu Routine
CVSS 9.1
CVE-2023-51747 HIGH
Apache James <3.8.1-3.7.5 - SMTP Smuggling
CVSS 7.1
Details
Vulnerabilities 12,465
Exploit Likelihood High