CWE-233 · 29 records
Improper Handling of Parameters
CVEs in this class
29 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-45182No exploit | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.pistar · pi-star digital voice dashboard · CWE-233 | Critical9.8 | — | 1.0% | Nov 11, 2022 |
37Monitor | CVE-2026-32998No exploit | This vulnerability in Veeam Service Provider Console allows for remote code execution.veeam · service provider console · CWE-233 | Critical9.4 | — | 0.6% | May 28, 2026 |
35Monitor | CVE-2025-52970Proof of concept | A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.fortinet · fortiweb · CWE-233 | High8.1 | — | 10.1% | Aug 12, 2025 |
35Monitor | CVE-2023-20076No exploit | Cisco IOx Application Hosting Environment Command Injection Vulnerabilitycisco · ic3000 industrial compute gateway · CWE-233 | High8.8 | — | 1.5% | Feb 12, 2023 |
35Monitor | CVE-2024-31808No exploit | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in totolink · ex200 firmware · CWE-233 | High8.8 | — | 0.9% | Apr 8, 2024 |
35Monitor | CVE-2021-0269No exploit | Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.juniper · junos · CWE-233 | High8.8 | — | 0.9% | Apr 22, 2021 |
35Monitor | CVE-2026-2370No exploit | Improper Handling of Parameters in GitLabgitlab · gitlab · CWE-233 | High8.8 | — | 0.4% | Mar 29, 2026 |
34Monitor | CVE-2023-20514No exploit | Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to funamd · amd radeon™ rx 6000 series graphics products · CWE-233 | High8.7 | — | 0.1% | Feb 11, 2026 |
31Monitor | CVE-2023-7261Proof of concept | Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalationgoogle · updater · CWE-233 | High7.8 | — | 0.2% | Jun 7, 2024 |
30Monitor | CVE-2021-1230No exploit | Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerabilitycisco · nx-os · CWE-233 | High7.5 | — | 1.5% | Feb 24, 2021 |
30Monitor | CVE-2022-3697No exploit | A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.redhat · ansible · CWE-233 | High7.5 | — | 0.8% | Oct 28, 2022 |
30Monitor | CVE-2022-32261No exploit | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).siemens · sinema remote connect server · CWE-233 | High7.5 | — | 0.7% | Jun 14, 2022 |
30Monitor | CVE-2022-22792No exploit | MobiSoft - MobiPlus User Take Over and Improper Handling of url Parametersmobisoft - mobiplus project · mobisoft - mobiplus · CWE-233 | High7.5 | — | 0.6% | Feb 16, 2022 |
30Monitor | CVE-2023-26549No exploit | The SystemUI module has a vulnerability of repeated app restart due to improper parameters.huawei · emui · CWE-233 | High7.5 | — | 0.4% | Mar 27, 2023 |
28Monitor | CVE-2025-55080No exploit | Improper Parameter Check in ThreadX Syscall Implementationeclipse · threadx · CWE-233 | High7.2 | — | 0.1% | Oct 15, 2025 |
27Monitor | CVE-2024-9329No exploit | Glassfish redirect to untrusted siteeclipse · glassfish · CWE-233 | Medium6.9 | — | 0.7% | Sep 30, 2024 |
27Monitor | CVE-2018-25233No exploit | WebDrive 18.00.5057 Denial of Service via Secure WebDAVsouthrivertech · webdrive · CWE-233 | Medium6.9 | — | 0.2% | Mar 30, 2026 |
26Monitor | CVE-2021-45478No exploit | IDOR in Yordam Library Automation Systemyordam · library automation system · CWE-233 | Medium6.5 | — | 0.6% | Mar 2, 2023 |
26Monitor | CVE-2021-45477No exploit | IDOR in Yordam Library Automation Systemyordam · library automation system · CWE-233 | Medium6.5 | — | 0.6% | Mar 2, 2023 |
26Monitor | CVE-2020-10069No exploit | Zephyr Bluetooth unchecked packet data results in denial of servicezephyrproject · zephyr · CWE-233 | Medium6.5 | — | 0.4% | May 25, 2021 |
26Monitor | CVE-2024-20306No exploit | A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker cisco · ios xe · CWE-233 | Medium6.7 | — | 0.2% | Mar 27, 2024 |
24Monitor | CVE-2026-0515No exploit | Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safetyblackberry ltd · qnx software development platform · CWE-233 | Medium6.2 | — | 0.1% | Jul 14, 2026 |
23Monitor | CVE-2023-1419No exploit | Debezium: script injection via connector parameterred hat · red hat build of debezium · CWE-233 | Medium5.9 | — | 0.4% | Nov 17, 2024 |
22Monitor | CVE-2025-55078No exploit | Incomplete validation of kernel object pointers in system callseclipse · threadx · CWE-233 | Medium5.7 | — | 0.2% | Oct 14, 2025 |
21Monitor | CVE-2024-25979No exploit | Msa-24-0002: forum search accepted random parameters in its urlmoodle · moodle · CWE-233 | Medium5.3 | — | 0.6% | Feb 19, 2024 |
- CVE-2022-4518239Monitor
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
CriticalCVSS 9.8No exploitEPSS 1%pistar · pi-star digital voice dashboardNov 11, 2022
- CVE-2026-3299837Monitor
This vulnerability in Veeam Service Provider Console allows for remote code execution.
CriticalCVSS 9.4No exploitEPSS 1%veeam · service provider consoleMay 28, 2026
- CVE-2025-5297035Monitor
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.
HighCVSS 8.1Proof of conceptEPSS 10%fortinet · fortiwebAug 12, 2025
- CVE-2023-2007635Monitor
Cisco IOx Application Hosting Environment Command Injection Vulnerability
HighCVSS 8.8No exploitEPSS 2%cisco · ic3000 industrial compute gatewayFeb 12, 2023
- CVE-2024-3180835Monitor
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in
HighCVSS 8.8No exploitEPSS 1%totolink · ex200 firmwareApr 8, 2024
- CVE-2021-026935Monitor
Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.
HighCVSS 8.8No exploitEPSS 1%juniper · junosApr 22, 2021
- CVE-2026-237035Monitor
Improper Handling of Parameters in GitLab
HighCVSS 8.8No exploitEPSS 0%gitlab · gitlabMar 29, 2026
- CVE-2023-2051434Monitor
Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to fun
HighCVSS 8.7No exploitEPSS 0%amd · amd radeon™ rx 6000 series graphics productsFeb 11, 2026
- CVE-2023-726131Monitor
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation
HighCVSS 7.8Proof of conceptEPSS 0%google · updaterJun 7, 2024
- CVE-2021-123030Monitor
Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 2%cisco · nx-osFeb 24, 2021
- CVE-2022-369730Monitor
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.
HighCVSS 7.5No exploitEPSS 1%redhat · ansibleOct 28, 2022
- CVE-2022-3226130Monitor
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).
HighCVSS 7.5No exploitEPSS 1%siemens · sinema remote connect serverJun 14, 2022
- CVE-2022-2279230Monitor
MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters
HighCVSS 7.5No exploitEPSS 1%mobisoft - mobiplus project · mobisoft - mobiplusFeb 16, 2022
- CVE-2023-2654930Monitor
The SystemUI module has a vulnerability of repeated app restart due to improper parameters.
HighCVSS 7.5No exploitEPSS 0%huawei · emuiMar 27, 2023
- CVE-2025-5508028Monitor
Improper Parameter Check in ThreadX Syscall Implementation
HighCVSS 7.2No exploitEPSS 0%eclipse · threadxOct 15, 2025
- CVE-2024-932927Monitor
Glassfish redirect to untrusted site
MediumCVSS 6.9No exploitEPSS 1%eclipse · glassfishSep 30, 2024
- CVE-2018-2523327Monitor
WebDrive 18.00.5057 Denial of Service via Secure WebDAV
MediumCVSS 6.9No exploitEPSS 0%southrivertech · webdriveMar 30, 2026
- CVE-2021-4547826Monitor
IDOR in Yordam Library Automation System
MediumCVSS 6.5No exploitEPSS 1%yordam · library automation systemMar 2, 2023
- CVE-2021-4547726Monitor
IDOR in Yordam Library Automation System
MediumCVSS 6.5No exploitEPSS 1%yordam · library automation systemMar 2, 2023
- CVE-2020-1006926Monitor
Zephyr Bluetooth unchecked packet data results in denial of service
MediumCVSS 6.5No exploitEPSS 0%zephyrproject · zephyrMay 25, 2021
- CVE-2024-2030626Monitor
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker
MediumCVSS 6.7No exploitEPSS 0%cisco · ios xeMar 27, 2024
- CVE-2026-051524Monitor
Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
MediumCVSS 6.2No exploitEPSS 0%blackberry ltd · qnx software development platformJul 14, 2026
- CVE-2023-141923Monitor
Debezium: script injection via connector parameter
MediumCVSS 5.9No exploitEPSS 0%red hat · red hat build of debeziumNov 17, 2024
- CVE-2025-5507822Monitor
Incomplete validation of kernel object pointers in system calls
MediumCVSS 5.7No exploitEPSS 0%eclipse · threadxOct 14, 2025
- CVE-2024-2597921Monitor
Msa-24-0002: forum search accepted random parameters in its url
MediumCVSS 5.3No exploitEPSS 1%moodle · moodleFeb 19, 2024