Skip to content
Noroxi

CWE-233 · 29 records

Improper Handling of Parameters

CVEs in this class

29 records

  • Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.

    CriticalCVSS 9.8No exploitEPSS 1%

    pistar · pi-star digital voice dashboardNov 11, 2022

  • This vulnerability in Veeam Service Provider Console allows for remote code execution.

    CriticalCVSS 9.4No exploitEPSS 1%

    veeam · service provider consoleMay 28, 2026

  • A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.

    HighCVSS 8.1Proof of conceptEPSS 10%

    fortinet · fortiwebAug 12, 2025

  • Cisco IOx Application Hosting Environment Command Injection Vulnerability

    HighCVSS 8.8No exploitEPSS 2%

    cisco · ic3000 industrial compute gatewayFeb 12, 2023

  • TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in

    HighCVSS 8.8No exploitEPSS 1%

    totolink · ex200 firmwareApr 8, 2024

  • CVE-2021-0269
    35Monitor

    Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.

    HighCVSS 8.8No exploitEPSS 1%

    juniper · junosApr 22, 2021

  • CVE-2026-2370
    35Monitor

    Improper Handling of Parameters in GitLab

    HighCVSS 8.8No exploitEPSS 0%

    gitlab · gitlabMar 29, 2026

  • Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to fun

    HighCVSS 8.7No exploitEPSS 0%

    amd · amd radeon™ rx 6000 series graphics productsFeb 11, 2026

  • CVE-2023-7261
    31Monitor

    Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation

    HighCVSS 7.8Proof of conceptEPSS 0%

    google · updaterJun 7, 2024

  • CVE-2021-1230
    30Monitor

    Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerability

    HighCVSS 7.5No exploitEPSS 2%

    cisco · nx-osFeb 24, 2021

  • CVE-2022-3697
    30Monitor

    A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.

    HighCVSS 7.5No exploitEPSS 1%

    redhat · ansibleOct 28, 2022

  • A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).

    HighCVSS 7.5No exploitEPSS 1%

    siemens · sinema remote connect serverJun 14, 2022

  • MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters

    HighCVSS 7.5No exploitEPSS 1%

    mobisoft - mobiplus project · mobisoft - mobiplusFeb 16, 2022

  • The SystemUI module has a vulnerability of repeated app restart due to improper parameters.

    HighCVSS 7.5No exploitEPSS 0%

    huawei · emuiMar 27, 2023

  • Improper Parameter Check in ThreadX Syscall Implementation

    HighCVSS 7.2No exploitEPSS 0%

    eclipse · threadxOct 15, 2025

  • CVE-2024-9329
    27Monitor

    Glassfish redirect to untrusted site

    MediumCVSS 6.9No exploitEPSS 1%

    eclipse · glassfishSep 30, 2024

  • WebDrive 18.00.5057 Denial of Service via Secure WebDAV

    MediumCVSS 6.9No exploitEPSS 0%

    southrivertech · webdriveMar 30, 2026

  • IDOR in Yordam Library Automation System

    MediumCVSS 6.5No exploitEPSS 1%

    yordam · library automation systemMar 2, 2023

  • IDOR in Yordam Library Automation System

    MediumCVSS 6.5No exploitEPSS 1%

    yordam · library automation systemMar 2, 2023

  • Zephyr Bluetooth unchecked packet data results in denial of service

    MediumCVSS 6.5No exploitEPSS 0%

    zephyrproject · zephyrMay 25, 2021

  • A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker

    MediumCVSS 6.7No exploitEPSS 0%

    cisco · ios xeMar 27, 2024

  • CVE-2026-0515
    24Monitor

    Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety

    MediumCVSS 6.2No exploitEPSS 0%

    blackberry ltd · qnx software development platformJul 14, 2026

  • CVE-2023-1419
    23Monitor

    Debezium: script injection via connector parameter

    MediumCVSS 5.9No exploitEPSS 0%

    red hat · red hat build of debeziumNov 17, 2024

  • Incomplete validation of kernel object pointers in system calls

    MediumCVSS 5.7No exploitEPSS 0%

    eclipse · threadxOct 14, 2025

  • Msa-24-0002: forum search accepted random parameters in its url

    MediumCVSS 5.3No exploitEPSS 1%

    moodle · moodleFeb 19, 2024

All vulnerability classes