← Back
CWE-233

31 CVEs • Abstraction: Base

Improper Handling of Parameters

The product does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.

JSON object

Loading...

CVEs (31)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 15, 2026
Jul 14, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
-
-
Jun 17, 2026
May 28, 2026
9.4 CRITICAL· v4
N/A· v3
N/A· v2
This vulnerability in Veeam Service Provider Console allows for remote code execution.
-
-
Jun 17, 2026
May 13, 2026
N/A· v4
3.8 LOW· v3
N/A· v2
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affect...Show more
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.Show less
1Southrivertech
1Webdrive
Apr 8, 2026
Mar 30, 2026
6.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
WebDrive 18.00.5057 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the username field during Secure WebDAV connection setup. Att...Show more
WebDrive 18.00.5057 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the username field during Secure WebDAV connection setup. Attackers can input a buffer-overflow payload of 5000 bytes in the username parameter and trigger a connection test to cause the application to crash.Show less
1Gitlab
1Gitlab
Jul 15, 2026
Mar 30, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated us...Show more
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.Show less
-
-
Jun 17, 2026
Feb 11, 2026
8.7 HIGH· v4
N/A· v3
N/A· v2
Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environment resulting in arbitrary code executio...Show more
Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environment resulting in arbitrary code executionShow less
-
-
Jun 17, 2026
Jan 30, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can cause abnormal device behavior by crafting specific messages.
1Eclipse
1Threadx
Jun 17, 2026
Oct 15, 2025
7.2 HIGH· v4
7.1 HIGH· v3
N/A· v2
In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.
1Eclipse
1Threadx
Jun 17, 2026
Oct 14, 2025
5.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check w...Show more
In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check wasn't verifying whether the pointer is outside the module memory region.Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Aug 12, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public info...Show more
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.Show less
-
-
Jun 17, 2026
Nov 17, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may...Show more
A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may allow the viewing of unauthorized data.Show less
1Eclipse
1Glassfish
Jun 17, 2026
Sep 30, 2024
6.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a...Show more
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.Show less
1Devlop.systems
1Id4portais
Jun 17, 2026
Aug 6, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.
1Google
1Updater
Jun 17, 2026
Jun 7, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
1Totolink
1X2000r Firmware
Jun 17, 2026
May 14, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
1Totolink
1Ex200 Firmware
Jun 17, 2026
Apr 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
1Cisco
1Ios Xe
Jun 17, 2026
Mar 27, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. T...Show more
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting a crafted CLI command to an affected device. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying operating system.Show less
1Epoint
1Epointwebbuilder
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Feb 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The URL parameters accepted by forum search were not limited to the allowed parameters.
1Skoda Auto
1Superb 3 Firmware
Jun 17, 2026
Jan 12, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows an attacker connected to the in-vehicle Wi-Fi ne...Show more
The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows an attacker connected to the in-vehicle Wi-Fi network to cause denial-of-service of the infotainment system, when the certain preconditions are met. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022. Show less