The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,467 vulnerabilities with CWE-20
CVE-2023-36888
MEDIUM
Microsoft Edge Chromium < 114.0.1823.82 - Tampering
CVSS 6.3
CVE-2023-3434
MEDIUM
Jami 20222284 - Denial of Service via Hyperlink Interpretation
CVSS 4.4
CVE-2023-3433
MEDIUM
Jami - Local Denial of Service via Nickname Field Special Character Injection
CVSS 5.5
CVE-2023-30559
MEDIUM
BD Alaris 8015 PCU Firmware < 12.1.3 - Unauthenticated Firmware Update Package Tampering
CVSS 5.2
CVE-2023-29457
MEDIUM
Zabbix Frontend 4.0.0-4.0.44 - Reflected Cross-Site Scripting via Action Form Fields
CVSS 6.3
CVE-2023-29456
MEDIUM
Zabbix Frontend 4.0.0-4.0.45 - Improper Input Validation in URL Validation Scheme
CVSS 5.7
CVE-2023-29455
MEDIUM
Zabbix Frontend 4.0.0-4.0.44 - Reflected Cross-Site Scripting
CVSS 5.4
CVE-2023-29454
MEDIUM
Zabbix Frontend 4.0.0-4.0.44 - Stored Cross-Site Scripting
CVSS 5.4
CVE-2023-29452
MEDIUM
Zabbix 6.0.0-6.0.16 - Stored Cross-Site Scripting in Geomap Attribution Text
CVSS 5.5
CVE-2023-29451
MEDIUM
Zabbix - Denial of Service via JSON Parser Buffer Overrun
CVSS 4.7
CVE-2023-37415
HIGH
Apache Airflow Apache Hive Provider < 6.1.2 - OS Command Injection via Proxy User Option
CVSS 8.8
CVE-2023-21251
HIGH
Android - Local Privilege Escalation via ConfirmDialog Input Validation Bypass
CVSS 7.3
CVE-2023-37948
LOW
Jenkins Oracle Cloud Infrastructure Compute Plugin < 1.0.17 - Man-in-the-Middle via Unvalidated SSH Host Keys
CVSS 3.7
CVE-2023-22888
MEDIUM
Apache Airflow < 2.6.3 - Authenticated Denial of Service via run_id Parameter
CVSS 6.5
CVE-2023-36872
MEDIUM
VP9 Video Extensions - Info Disclosure
CVSS 5.5
CVE-2023-35367
CRITICAL
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 9.8
CVE-2023-35366
CRITICAL
Windows RRAS - Remote Code Execution via Improper Input Validation
CVSS 9.8
CVE-2023-35365
CRITICAL
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 9.8
CVE-2023-35336
MEDIUM
Windows 10 1507-22H2, Windows 11 21H2-22H2, Windows Server 2012-2022 - Security Feature Bypass in MSHTML Platform
CVSS 6.5
CVE-2023-35306
MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure via PostScript and PCL6 Printer Driver
CVSS 5.5
CVE-2023-35303
HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution in USB Audio Class System Driver
CVSS 8.8
CVE-2023-32057
CRITICAL
Microsoft Windows MSMQ - Remote Code Execution via Improper Input Validation
CVSS 9.8
CVE-2023-32037
MEDIUM
Windows Layer-2 Bridge - Info Disclosure
CVSS 6.5
CVE-2023-22835
HIGH
Palantir Foundry Issues < 2.510.0 and Foundry Frontend < 6.228.0 - Denial of Service via Malformed Issue Data
CVSS 7.7
CVE-2023-30449
HIGH
IBM Db2 10.5, 11.1, 11.5 - Denial of Service via Crafted Query
CVSS 7.5
Details
Vulnerabilities
12,467
Exploit Likelihood
High