CWE-233: Improper Handling of Parameters
The product does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.
23 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-2370 — Improper Handling of Parameters in GitLab
- CVE-2025-52970 — A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
- CVE-2026-32998 — This vulnerability in Veeam Service Provider Console allows for remote code execution.
- CVE-2025-55080 — Improper Parameter Check in ThreadX Syscall Implementation
- CVE-2024-9329 — Glassfish redirect to untrusted site
- CVE-2018-25233 — WebDrive 18.00.5057 Denial of Service via Secure WebDAV
- CVE-2024-20306 — A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authentica
- CVE-2025-55078 — Incomplete validation of kernel object pointers in system calls
- CVE-2026-0515 — Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
- CVE-2026-33585 — Arqit SKA-Platform Improper Handling of Parameters Vulnerability
Recently published
- CVE-2026-0515 — Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
- CVE-2026-32998 — This vulnerability in Veeam Service Provider Console allows for remote code execution.
- CVE-2026-33585 — Arqit SKA-Platform Improper Handling of Parameters Vulnerability
- CVE-2018-25233 — WebDrive 18.00.5057 Denial of Service via Secure WebDAV
- CVE-2026-2370 — Improper Handling of Parameters in GitLab
- CVE-2025-55080 — Improper Parameter Check in ThreadX Syscall Implementation
- CVE-2025-55078 — Incomplete validation of kernel object pointers in system calls
- CVE-2025-52970 — A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
- CVE-2024-9329 — Glassfish redirect to untrusted site
- CVE-2024-20306 — A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authentica