CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,466 vulnerabilities with CWE-20
CVE-2023-41782 LOW
ZTE ZXCLOUD iRAI < 7.23.30 - DLL Hijacking via Uncontrolled Search Path
CVSS 3.9
CVE-2023-6992 MEDIUM
Cloudflare zlib < 2023-11-16 - Denial of Service via Deflation Algorithm Memory Corruption
CVSS 4.0
CVE-2023-6738 MEDIUM
Page Builder: Pagelayer < 1.7.8 - Authenticated Stored Cross-Site Scripting via Header/Body/Footer Code Meta Fields
CVSS 5.4
CVE-2023-50256 HIGH
froxlor < 2.1.2 - Improper Input Validation via Registration Form Bypass
CVSS 7.5
CVE-2023-46929 HIGH
GPAC 2.3-DEV-rev605-gfc9e29089-master - Denial of Service in MP4Box AVC VUI Parser
CVSS 7.5
CVE-2023-49551 HIGH
Cesanta mjs 2.20.0 - Denial of Service via mjs_op_json_parse Function
CVSS 7.5
CVE-2023-33014 HIGH
Qualcomm AR8035 Firmware - Information Disclosure via Diag Command Processing
CVSS 7.6
CVE-2023-26159 HIGH
follow-redirects < 1.15.4 - URL Redirection to Untrusted Site via Improper Hostname Parsing
CVSS 7.3
CVE-2023-32890 HIGH
MediaTek LR13 NR15 NR16 NR17 - Remote Denial of Service via Modem EMM Input Validation
CVSS 7.5
CVE-2023-49299 HIGH
Apache DolphinScheduler <3.1.9 - XSS
CVSS 8.8
CVE-2023-52137 HIGH
tj-actions/verify-changed-files < 17.0.0 - Command Injection via Changed Filename Special Characters
CVSS 7.7
CVE-2023-47804 HIGH
Apache OpenOffice < 4.1.15 - Unauthenticated Arbitrary Script Execution via Macro Link Activation
CVSS 8.8
CVE-2023-7163 CRITICAL
D-Link D-View 8 <= 2.0.2.89 - Improper Input Validation in Probe Inventory
CVSS 10.0
CVE-2023-6879 CRITICAL
aomedia < 3.7.1 - Heap Overflow via Multi-Threaded Video Frame Resolution Increase
CVSS 9.0
CVE-2023-31455 HIGH
Pexip Infinity <31.2 - Buffer Overflow
CVSS 7.5
CVE-2023-31289 HIGH
Pexip Infinity <31.2 - Remote Code Execution
CVSS 7.5
CVE-2023-39251 MEDIUM
Dell BIOS < 1.27.0 - Memory Corruption via Improper Input Validation
CVSS 6.7
CVE-2023-45165 MEDIUM
IBM AIX 7.2 and 7.3 - Denial of Service via SMB Client
CVSS 6.2
CVE-2023-6784 MEDIUM
Progress Sitefinity 4.0-13.3.7648 - Phishing Email Distribution
CVSS 4.7
CVE-2023-0011 HIGH
u-blox TOBY-L2 Series - OS Command Injection via AT Commands
CVSS 7.6
CVE-2023-47705 MEDIUM
IBM Security Guardium Key Lifecycle Manager 4.2.0-4.2.0.1 Username Manipulation via Input Validation
CVSS 4.3
CVE-2023-47161 MEDIUM
IBM UrbanCode Deploy 7.0.0.0-7.0.5.18 - Denial of Service via Archive File Upload
CVSS 5.3
CVE-2023-42012 MEDIUM
IBM UrbanCode Deploy 7.2.0.0-7.2.3.7 and 7.3.0.0-7.3.2.2 - Denial of Service via Windows Service Path
CVSS 6.2
CVE-2023-45172 MEDIUM
IBM AIX 7.2-7.3 and VIOS 3.1 - Denial of Service via AIX Windows
CVSS 6.2
CVE-2023-22439 LOW
Gallagher Controller <8.90.231204a-8.80.1369-8.70.2375-8.60.231116a...
CVSS 3.1
Details
Vulnerabilities 12,466
Exploit Likelihood High