The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
122 vulnerabilities with CWE-184
CVE-2024-52595
HIGH
lxml_html_clean < 0.4.0 - Cross-Site Scripting via Improper Context-Switching Tag Handling
CVSS 7.7
CVE-2024-51745
CRITICAL
Wasmtime < 24.0.2 - Unauthenticated Filesystem Sandbox Bypass via Superscript Digit Device Filenames
CVSS 10.0
CVE-2024-32152
LOW
Anki < 24.6 - Arbitrary File Creation via LaTeX Blocklist Bypass
CVSS 3.1
CVE-2024-5217
CRITICAL
KEV
ServiceNow Washington DC and Vancouver - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-5178
MEDIUM
ServiceNow Now Platform - Sensitive File Read via Unauthorized Access
CVSS 4.9
CVE-2024-30103
HIGH
Microsoft Outlook - Remote Code Execution
CVSS 8.8
CVE-2024-23336
MEDIUM
MyBB < 1.8.38 - Server-Side Request Forgery via Incomplete Disallowed Remote Addresses List
CVSS 5.0
CVE-2024-20278
MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.5
CVE-2024-28246
MEDIUM
KaTeX 0.11.0-0.16.9 - Cross-Site Scripting via Uppercase Protocol Bypass
CVSS 5.5
CVE-2023-45593
MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Info Disclosure
CVSS 6.8
CVE-2023-45133
CRITICAL
Babel traverse <7.23.2 and 8.0.0-alpha.4 - Code Execution via path.evaluate
CVSS 9.3
CVE-2023-3374
CRITICAL
Unisign Bookreen <3.0.0 - Privilege Escalation
CVSS 9.8
CVE-2023-40037
MEDIUM
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
CVSS 6.5
CVE-2023-23844
HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-34253
HIGH
Grav < 1.7.42 - Authenticated Remote Code Execution via Template Injection Denylist Bypass
CVSS 8.8
CVE-2023-34252
HIGH
Grav < 1.7.42 - Authenticated Remote Code Execution via Twig Filter Array Bypass
CVSS 8.8
CVE-2023-2017
HIGH
Shopware 6 <= v6.4.20.0,v6.5.0.0-rc1 <= v6.5.0.0-rc4 - Code Injection
CVSS 8.8
CVE-2023-29003
HIGH
SvelteKit < 1.15.1 - CSRF Protection Bypass via Content-Type Header
CVSS 8.8
CVE-2022-50238
HIGH
Windows < Server 2025 - Incomplete Driver Blocklist Synchronization
CVSS 7.4
CVE-2022-34888
LOW
Lenovo ThinkAgile VX3331 Firmware < 1.80_afbt20n - Authenticated Internal Service Access via Remote Mount Feature
CVSS 2.7
CVE-2022-43396
HIGH
Blacklist Bypass - Command Injection
CVSS 8.8
CVE-2022-23536
MEDIUM
Cortex <1.14.0 - Local File Inclusion
CVSS 6.5
CVE-2022-32763
MEDIUM
Lansweeper 10.1.1.0 - Cross-Site Scripting via SanitizeHtml Bypass
CVSS 6.1
CVE-2022-35962
HIGH
Zulip Mobile <27.189 - Info Disclosure
CVSS 8.0
CVE-2022-38179
MEDIUM
JetBrains Ktor <2.1.0 - Code Injection
CVSS 4.7
Details
Vulnerabilities
122