The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
161 vulnerabilities with CWE-184
CVE-2023-3374
CRITICAL
Unisign Bookreen <3.0.0 - Privilege Escalation
CVSS 9.8
CVE-2023-40037
MEDIUM
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
CVSS 6.5
CVE-2023-23844
HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-34253
HIGH
Grav < 1.7.42 - Authenticated Remote Code Execution via Template Injection Denylist Bypass
CVSS 8.8
CVE-2023-34252
HIGH
Grav < 1.7.42 - Authenticated Remote Code Execution via Twig Filter Array Bypass
CVSS 8.8
CVE-2023-2017
HIGH
Shopware 6 <= v6.4.20.0,v6.5.0.0-rc1 <= v6.5.0.0-rc4 - Code Injection
CVSS 8.8
CVE-2023-29003
HIGH
SvelteKit < 1.15.1 - CSRF Protection Bypass via Content-Type Header
CVSS 8.8
CVE-2022-50238
HIGH
Windows < Server 2025 - Incomplete Driver Blocklist Synchronization
CVSS 7.4
CVE-2022-34888
LOW
Lenovo ThinkAgile VX3331 Firmware < 1.80_afbt20n - Authenticated Internal Service Access via Remote Mount Feature
CVSS 2.7
CVE-2022-43396
HIGH
Blacklist Bypass - Command Injection
CVSS 8.8
CVE-2022-23536
MEDIUM
Cortex <1.14.0 - Local File Inclusion
CVSS 6.5
CVE-2022-32763
MEDIUM
Lansweeper 10.1.1.0 - Cross-Site Scripting via SanitizeHtml Bypass
CVSS 6.1
CVE-2022-35962
HIGH
Zulip Mobile <27.189 - Info Disclosure
CVSS 8.0
CVE-2022-38179
MEDIUM
JetBrains Ktor <2.1.0 - Code Injection
CVSS 4.7
CVE-2021-31370
MEDIUM
Juniper Junos OS QFX5000/EX4600 <21.1R2 DoS via High-Rate Multicast Traffic
CVSS 6.5
CVE-2021-25737
LOW
Kubernetes 1.16.0-1.18.18 - Unauthenticated Private Network Traffic Redirection via EndpointSlice IP Validation Bypass
CVSS 2.7
CVE-2021-25631
HIGH
LibreOffice <7.1.2 & <7.0.5 - Code Injection
CVSS 8.8
CVE-2021-1135
MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated Unauthorized Data Access via REST API
CVSS 4.6
CVE-2021-1255
MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated REST API Authorization Bypass
CVSS 4.6
CVE-2021-1133
MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated REST API Authorization Bypass
CVSS 4.6
CVE-2020-14372
HIGH
GRUB2 < 2.06 - Secure Boot Bypass via ACPI Table Injection
CVSS 7.5
CVE-2020-3384
HIGH
Cisco Data Center Network Manager < 11.4(1) - Authenticated OS Command Injection via REST API
CVSS 8.2
CVE-2020-5253
LOW
NetHack < 3.6.0 - Arbitrary Code Execution via Configuration File Escape Sequence
CVSS 3.9
CVE-2019-9212
CRITICAL
SOFA-Hessian < 4.0.2 - Remote Code Execution via Hessian Deserialization
CVSS 9.8
CVE-2018-16863
HIGH
Ghostscript 9.07 - Remote Code Execution via PostScript Document
CVSS 7.3
Details
Vulnerabilities
161