CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-20270 MEDIUM
Cisco Firepower Threat Defense - Denial of Service via SMB Protocol Preprocessor
CVSS 5.8
CVE-2023-20114 MEDIUM
Cisco Firepower Management Center - RCE
CVSS 6.5
CVE-2023-40062 HIGH
SolarWinds Platform < 2023.4 - Remote Code Execution via Incomplete List of Disallowed Inputs
CVSS 8.0
CVE-2023-40061 HIGH
SolarWinds Platform < 2023.4 - Insecure Job Execution Mechanism
CVSS 8.8
CVE-2023-4197 HIGH
Dolibarr ERP CRM <= 18.0.1 - Remote Code Execution via Website Input
CVSS 7.5
CVE-2023-37833 LOW
Elenos ETG150 FM Transmitter 3.12 - Improper Access Control
CVSS 2.7
CVE-2023-3955 HIGH
Kubernetes < 1.24.17 and 1.28.0 - Privilege Escalation via Windows Pod Creation
CVSS 8.8
CVE-2023-3676 HIGH
kubernetes <1.24.17, >=1.28.0 <1.28.1 - Privilege Escalation via Windows Pod Creation
CVSS 8.8
CVE-2023-21391 HIGH
Android < 14.0 - Remote Denial of Service via Messaging Input Validation
CVSS 7.5
CVE-2023-5832 CRITICAL
AnythingLLM < 0.1.0 - Improper Input Validation
CVSS 9.1
CVE-2023-42431 LOW
BlueSpice 3.0-3.2.10.1 - Authenticated Stored Cross-Site Scripting in Profile Image Dialog
CVSS 2.1
CVE-2023-46289 HIGH
Rockwell Automation FactoryTalk View Site Edition - DoS
CVSS 7.5
CVE-2023-5624 HIGH
Nessus Network Monitor < 6.3.0 - Authenticated Blind SQL Injection via Parameter Alteration
CVSS 7.2
CVE-2023-5044 HIGH
ingress-nginx < 1.9.0 - Code Injection via nginx.ingress.kubernetes.io/permanent-redirect Annotation
CVSS 7.6
CVE-2023-5043 HIGH
ingress-nginx < 1.9.0 - OS Command Injection via Annotation
CVSS 7.6
CVE-2023-45805 HIGH
PDM 2.0.0-2.9.3 - Dependency Confusion via Malicious pdm.lock File
CVSS 7.8
CVE-2023-39456 HIGH
Apache Traffic Server 9.0.0-9.2.2 - Improper Input Validation via Malformed HTTP/2 Frames
CVSS 7.5
CVE-2023-40373 MEDIUM
IBM Db2 11.5-11.5.8 - Denial of Service via Crafted Query with Common Table Expressions
CVSS 5.3
CVE-2023-40372 MEDIUM
IBM Db2 11.5-11.5.8 - Denial of Service via External Tables SQL Statement
CVSS 5.3
CVE-2023-38719 MEDIUM
IBM Db2 11.5 - Denial of Service during Database Deactivation on DPF
CVSS 5.1
CVE-2023-40374 MEDIUM
IBM Db2 11.5-11.5.8 - Denial of Service via Crafted Query Statement
CVSS 5.3
CVE-2023-30991 HIGH
IBM Db2 11.1-11.5 - Denial of Service via Specially Crafted Query
CVSS 7.5
CVE-2023-38740 MEDIUM
IBM Db2 11.5-11.5.8 - Denial of Service via Crafted SQL Statement
CVSS 5.3
CVE-2023-38728 MEDIUM
IBM Db2 10.5, 11.1, <11.5.8 - Denial of Service via Crafted XML Query Statement
CVSS 5.3
CVE-2023-45128 CRITICAL
Fiber < 2.50.0 - Cross-Site Request Forgery via Improper CSRF Token Validation
CVSS 10.0
Details
Vulnerabilities 12,467
Exploit Likelihood High