CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,466 vulnerabilities with CWE-20
CVE-2023-41268 MEDIUM
Samsung Open Source Escargot <4.0.0 - Buffer Overflow
CVSS 5.3
CVE-2023-40053 MEDIUM
SolarWinds Serv-U 15.4 - Authenticated Arbitrary File Write via File Share Function
CVSS 5.0
CVE-2023-5188 HIGH
WAGO Telecontrol Configurator and WagoAppRTU < 1.4.6.0 - Unauthenticated Denial of Service via Malformed MMS Packets
CVSS 7.5
CVE-2023-33042 HIGH
Qualcomm 315 5G IoT Modem Firmware - Denial of Service via RRC Setup Message
CVSS 7.5
CVE-2023-48693 HIGH
Azure RTOS ThreadX <6.3.0 - Privilege Escalation
CVSS 8.7
CVE-2023-49291 CRITICAL
tj-actions/branch-names < 7.0.7 - Remote Code Execution via Crafted Branch Name
CVSS 9.3
CVE-2023-40097 HIGH
Android - Local Privilege Escalation via URI Grant in PackageManagerHelper
CVSS 7.8
CVE-2023-47106 MEDIUM
Traefik < 2.10.6 and < 3.0.0-beta5 - URL Fragment Forwarding Bypass
CVSS 4.8
CVE-2023-40687 MEDIUM
IBM DB2 < 10.5.0.11 - Denial of Service via RUNSTATS Command
CVSS 5.3
CVE-2023-38727 MEDIUM
IBM Db2 10.5.0.0-10.5.0.10 - Denial of Service via Crafted SQL Statement
CVSS 5.3
CVE-2023-29258 MEDIUM
IBM Db2 11.1-11.5 - Denial of Service via Federated Query
CVSS 5.3
CVE-2023-47701 MEDIUM
IBM Db2 10.5.0.0-10.5.0.10 - Denial of Service via Crafted Query
CVSS 6.5
CVE-2023-46167 MEDIUM
IBM Db2 11.5.6-11.5.8 - Denial of Service via Specially Crafted Cursor
CVSS 5.9
CVE-2023-45178 MEDIUM
IBM Db2 11.5 CLI - Denial of Service via Specially Crafted Request
CVSS 6.5
CVE-2023-40699 HIGH
IBM InfoSphere Information Server 11.7 - DoS
CVSS 7.5
CVE-2023-34390 MEDIUM
SEL-451 Firmware r315-v0-r315-v4 - Authenticated Denial of Service via Input Validation Issue
CVSS 4.5
CVE-2023-2267 MEDIUM
SEL-411L Firmware r118-v0 to r118-v4 - Reflection Attack via Improper Input Validation
CVSS 4.3
CVE-2023-2264 MEDIUM
SEL-411L Firmware r118-v0 to r118-v4 - Improper Input Validation
CVSS 4.0
CVE-2023-49095 HIGH
nexkey < 12.122.2 - User Impersonation via ActivityPub Request Validation Bypass
CVSS 8.6
CVE-2023-49081 HIGH
aiohttp < 3.9.0 - HTTP Request Smuggling via HTTP Version Manipulation
CVSS 7.2
CVE-2023-5275 LOW
GX Works2 - Denial of Service via Simulation Function Packet Handling
CVSS 2.5
CVE-2023-5274 LOW
GX Works2 - Denial of Service via Simulation Function Packet Handling
CVSS 2.5
CVE-2023-49082 MEDIUM
aiohttp < 3.9.0 - HTTP Request Smuggling via CRLF Injection
CVSS 5.3
CVE-2023-35136 MEDIUM
Zyxel ZLD 4.32-5.37 - Authenticated Configuration File Access via Quagga Package Input Validation
CVSS 5.5
CVE-2023-48226 MEDIUM
OpenReplay < 1.15.0 - HTML Injection in Account Settings Name Field
CVSS 6.5
Details
Vulnerabilities 12,466
Exploit Likelihood High