The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
134 vulnerabilities with CWE-1287
CVE-2024-20494
HIGH
Cisco Adaptive Security Appliance Software - Denial of Service via TLS 1.3 Handshake
CVSS 8.6
CVE-2024-20408
HIGH
Cisco ASA Software DoS via Dynamic Access Policies HTTPS POST Request
CVSS 7.7
CVE-2024-47504
HIGH
Juniper Junos OS - Unauthenticated Denial of Service via Malformed Packet in Packet Forwarding Engine
CVSS 7.5
CVE-2024-1578
MEDIUM
rf IDEAS MiCard PLUS Ci/MiCard PLUS BLE - Info Disclosure
CVSS 5.3
CVE-2024-3175
MEDIUM
Google Chrome <120.0.6099.62 - Privilege Escalation
CVSS 6.3
CVE-2024-4879
CRITICAL
KEV
ServiceNow Vancouver and Washington DC - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-6298
CRITICAL
ABB ASPECT Enterprise, NEXUS Series, MATRIX Series <3.08.01 - Unauthorized File Access
CVSS 10.0
CVE-2024-35213
CRITICAL
QNX Software Development Platform 6.6-7.1 - Denial of Service or Remote Code Execution in SGI Image Codec
CVSS 9.0
CVE-2024-30395
HIGH
Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via Malformed BGP Tunnel Encapsulation TLV
CVSS 7.5
CVE-2024-31948
MEDIUM
FRRouting < 9.1 - Denial of Service via Malformed Prefix SID Attribute in BGP UPDATE Packet
CVSS 6.5
CVE-2023-29126
MEDIUM
Enel X Waybox Pro Firmware < 2.1.1.0_jb3vu096a - Authentication Bypass via PHP Type Juggling
CVSS 4.2
CVE-2023-47726
HIGH
IBM QRadar Suite Software <1.10.21.0 - Command Injection
CVSS 7.1
CVE-2023-47727
MEDIUM
IBM Cloud Pak for Security <1.10.11.0 & QRadar Suite Software <1.10...
CVSS 4.3
CVE-2023-32651
MEDIUM
Intel PROSet/Wireless and Killer Wi-Fi < 22.240 - Unauthenticated Denial of Service via Adjacent Access
CVSS 4.3
CVE-2023-3904
MEDIUM
GitLab EE <16.4.4-16.5.4-16.6.2 - Buffer Overflow
CVSS 4.3
CVE-2023-3917
MEDIUM
GitLab < 16.2.8, 16.3 < 16.3.5, 16.4 < 16.4.1 - Denial of Service in Pipelines
CVSS 4.3
CVE-2023-3906
LOW
GitLab EE <16.2.8-16.4.1 - Auth Bypass
CVSS 3.5
CVE-2023-4522
MEDIUM
GitLab < 16.2.0 - Denial of Service via Directory Names with LF Characters
CVSS 4.3
CVE-2023-3900
MEDIUM
GitLab 16.1-16.1.3 and 16.2-16.2.2 - Denial of Service via Invalid 'start_sha' Value
CVSS 4.3
CVE-2023-28799
HIGH
Zscaler Client Connector < 1.4, < 1.9.3, < 1.10.1, < 1.10.2, < 3.7, < 3.9 - Open Redirect via Login URL Parameter
CVSS 8.2
CVE-2023-2431
LOW
Kubernetes < 1.24.14 - Seccomp Profile Enforcement Bypass via Empty Profile Field
CVSS 3.4
CVE-2023-2673
MEDIUM
PHOENIX CONTACT FL/TC MGUARD Family - UDP Packet Filter Bypass via Improper Input Validation
CVSS 5.3
CVE-2022-43723
HIGH
SICAM PAS/PQS < V7.0 or >= 7.0 < V8.06 - DoS
CVSS 7.5
CVE-2022-39369
HIGH
phpCAS <1.6.0 - Account Access via Host Header Service URL Confusion
CVSS 8.0
CVE-2022-22228
HIGH
Juniper Networks Junos OS <21.1R3-S2-21.4 - DoS
CVSS 7.5
Details
Vulnerabilities
134