CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-36407 HIGH
Windows Hyper-V - Privilege Escalation
CVSS 7.8
CVE-2023-36406 MEDIUM
Windows 11/Server 2022 Information Disclosure (21H2<22000.2600, 22H2<22621.2715, 23H2<22631.2715, Server 23H2<25398.531)
CVSS 5.5
CVE-2023-36021 HIGH
Microsoft On-Prem Data Gateway - Privilege Escalation
CVSS 8.0
CVE-2023-6073 MEDIUM
Volkswagen ID.3 Firmware < 3.2 - Denial of Service and Volume Setting Spoofing via REST API
CVSS 5.7
CVE-2023-45167 MEDIUM
IBM AIX 7.3 - Denial of Service via Python Uncontrolled Resource Consumption
CVSS 6.2
CVE-2023-5079 HIGH
Lenovo LeCloud App - Info Disclosure
CVSS 7.5
CVE-2023-43570 MEDIUM
Lenovo IdeaCentre and ThinkCentre Firmware - Authenticated Arbitrary Code Execution via SMI Callback Function
CVSS 6.7
CVE-2023-47107 HIGH
PILOS 2.0.0-2.2.9 - Password Reset Token Disclosure via Host Header Manipulation
CVSS 8.8
CVE-2023-6012 HIGH
Lanaccess ONSAFE MonitorHM <3.7.0 - RCE
CVSS 8.3
CVE-2023-46763 MEDIUM
Framework Module - Privilege Escalation
CVSS 5.3
CVE-2023-39913 HIGH
Apache UIMA Java SDK < 3.5.0 - Remote Code Execution via Untrusted Java Deserialization
CVSS 8.8
CVE-2023-46851 MEDIUM
Apache Allura <1.16.0 - Info Disclosure
CVSS 4.9
CVE-2023-42527 MEDIUM
Samsung Android - Information Exposure via ProcessWriteFile Input Validation
CVSS 5.6
CVE-2023-28574 CRITICAL
Qualcomm Diag Handler Firmware - Memory Corruption
CVSS 9.0
CVE-2023-21671 CRITICAL
Qualcomm FastConnect and QCA6391/QCM6490/QCS6490/QSM8350 Firmware - Memory Corruption in Sectools Fuse
CVSS 9.3
CVE-2023-5964 CRITICAL
1E Platform < 23.0 - Remote Code Execution via End-User Interaction DisplayMessage Instruction
CVSS 9.9
CVE-2023-45163 CRITICAL
1E Platform < 18.1 - Remote Code Execution via CommandLinePing Instruction Input
CVSS 9.9
CVE-2023-45161 CRITICAL
1e platform < 20.1 - Remote Code Execution via URL Parameter in 1E-Exchange-URLResponseTime Instruction
CVSS 9.9
CVE-2023-3893 HIGH
kubernetes-csi/csi-proxy <1.1.3 and 2.0.0-alpha.0 - Privilege Escalation via Pod Creation
CVSS 8.8
CVE-2023-4043 MEDIUM
Eclipse Parsson <1.1.4-1.0.5 - Info Disclosure
CVSS 5.9
CVE-2023-5763 MEDIUM
Eclipse Glassfish 5.0.0-6.2.4 - Remote Code Execution via Insecure ORB Listeners
CVSS 6.8
CVE-2023-41355 CRITICAL
Chunghwa Telecom NOKIA G-040W-Q - DoS
CVSS 9.8
CVE-2023-42802 CRITICAL
GLPI 10.0.7-10.0.9 - Unrestricted Upload of File with Dangerous Type via Unverified Object Instantiation
CVSS 10.0
CVE-2023-20255 MEDIUM
Cisco Meeting Server < 3.6.1 - Unauthenticated Denial of Service via Web Bridge API HTTP Request
CVSS 5.3
CVE-2023-20063 HIGH
Cisco Firepower 6.2.3 Authenticated RCE via Expert Mode Command Injection
CVSS 8.2
Details
Vulnerabilities 12,467
Exploit Likelihood High