CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,467 vulnerabilities with CWE-20
CVE-2023-40165 HIGH
rubygems.org < 2023-08-14 - Unauthenticated Gem Replacement via Insufficient Input Validation
CVSS 7.4
CVE-2023-2917 CRITICAL
ThinManager Path Traversal (CVE-2023-2917) Arbitrary File Upload
CVSS 9.8
CVE-2023-2915 HIGH
ThinManager Path Traversal (CVE-2023-2915) Arbitrary File Delete
CVSS 7.5
CVE-2023-2914 HIGH
Rockwell Automation ThinManager ThinServer 11.0.0-11.0.5 DoS via Crafted Sync Message
CVSS 7.5
CVE-2023-40272 HIGH
Apache Airflow Spark Provider < 4.1.3 - Arbitrary File Read via Connection Parameters
CVSS 7.5
CVE-2023-20232 MEDIUM
Cisco Unified CCX - Web Cache Poisoning
CVSS 5.3
CVE-2023-40034 HIGH
woodpecker 1.0.0-1.0.1 - Repository Takeover via Malformed Webhook Data
CVSS 8.1
CVE-2023-38737 MEDIUM
IBM WebSphere Application Server Liberty <23.0.0.7 - DoS
CVSS 5.9
CVE-2023-4241 HIGH
lol-html < 1.1.1 - Denial of Service via Malformed HTML Input
CVSS 7.5
CVE-2023-20564 MEDIUM
AMD Ryzen Master < 2.11.2.2659 - Privileged Memory Read/Write via IOCTL Input Buffer
CVSS 6.7
CVE-2023-20560 MEDIUM
AMD Ryzen Master < 2.11.2.2659 - Denial of Service via IOCTL Input Buffer
CVSS 4.4
CVE-2023-4357 HIGH
Google Chrome <116.0.5845.96 - Auth Bypass
CVSS 8.8
CVE-2023-21284 MEDIUM
Android - Denial of Service via Find My Device Feature Manipulation
CVSS 5.5
CVE-2023-21272 HIGH
Android - Local Privilege Escalation via URI Permission Grant
CVSS 7.8
CVE-2023-39950 MEDIUM
efibootguard < 0.15 - Improper Input Validation in Bootloader Environment Files
CVSS 6.1
CVE-2023-39404 HIGH
Huawei EMUI and HarmonyOS - Denial of Service via Window Management API Input Parameter
CVSS 7.5
CVE-2023-39390 HIGH
Window Management Module - Info Disclosure
CVSS 7.5
CVE-2023-39386 HIGH
Huawei EMUI and HarmonyOS - Denial of Service via PMS Module Input Parameter
CVSS 7.5
CVE-2023-39405 CRITICAL
Huawei EMUI and HarmonyOS - Out-of-Bounds Read/Write in Wi-Fi Module
CVSS 9.8
CVE-2023-39389 HIGH
Huawei EMUI and HarmonyOS - Denial of Service in PMS Module
CVSS 7.5
CVE-2023-39388 HIGH
Huawei EMUI and HarmonyOS - Denial of Service in PMS Module
CVSS 7.5
CVE-2023-39382 HIGH
Huawei EMUI and HarmonyOS - Denial of Service via Audio Module Input Verification
CVSS 7.5
CVE-2023-39381 HIGH
Huawei EMUI and HarmonyOS - Input Verification Vulnerability in Storage Module
CVSS 7.5
CVE-2023-39553 HIGH
Apache Airflow Drill Provider < 2.4.3 - Unauthenticated Arbitrary File Read via DrillHook Connection Parameters
CVSS 7.5
CVE-2023-34086 HIGH
Intel(R) NUC BIOS - Privilege Escalation
CVSS 8.2
Details
Vulnerabilities 12,467
Exploit Likelihood High