The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,467 vulnerabilities with CWE-20
CVE-2023-32305
HIGH
aiven-extras < 1.1.9 - Privilege Escalation via Unqualified Function Name Collision
CVSS 8.8
CVE-2023-25927
MEDIUM
IBM Security Verify Access 10.0.0-10.0.5 - Denial of Service via Crafted HTTP Requests
CVSS 6.5
CVE-2023-29246
HIGH
Apache OpenMeetings <7.1.0 - Privilege Escalation
CVSS 7.2
CVE-2023-29195
MEDIUM
Vitess < 16.0.2 - Denial of Service via Shard Creation with Slash Characters
CVSS 4.1
CVE-2023-29026
MEDIUM
Rockwell Automation's ArmorStart ST - XSS
CVSS 4.7
CVE-2023-32075
MEDIUM
pimcore customer_management_framework < 3.3.9 - Business Logic Error via Conditions Tab Counter
CVSS 4.3
CVE-2023-31162
MEDIUM
SEL RTAC Module Firmware r149-v0-r150-v2 - Authenticated Arbitrary File Write via Web Interface
CVSS 4.8
CVE-2023-31161
MEDIUM
SEL RTAC Web Interface - Authenticated Improper Input Validation
CVSS 5.9
CVE-2023-31149
CRITICAL
SEL RTAC Web Interface - Authenticated Remote Code Execution
CVSS 9.1
CVE-2023-31148
CRITICAL
SEL RTAC Web Interface - Authenticated Remote Code Execution
CVSS 9.1
CVE-2023-25776
MEDIUM
Intel Server System Firmware < 2.90 - Authenticated Information Disclosure via Improper Input Validation
CVSS 6.3
CVE-2023-25772
MEDIUM
Intel Retail Edge Mobile Android < 3.0.301126-RELEASE - Authenticated Denial of Service via Local Access
CVSS 5.0
CVE-2023-25175
MEDIUM
Intel Server Board BMC Firmware < 2.90 - Authenticated Information Disclosure via Improper Input Validation
CVSS 6.1
CVE-2023-22379
MEDIUM
Intel(R) Server Board BMC <2.90 - Info Disclosure
CVSS 6.7
CVE-2023-1732
MEDIUM
cloudflare/circl < 1.3.3 - Predictable Shared Secret via Insufficient Randomness Check
CVSS 5.3
CVE-2023-29335
HIGH
Microsoft Word - Security Feature Bypass via Improper Input Validation
CVSS 7.5
CVE-2023-24950
MEDIUM
Microsoft SharePoint Server - Spoofing
CVSS 6.5
CVE-2023-28200
MEDIUM
iPadOS < 15.7.4 - Kernel Memory Disclosure via Input Validation Issue
CVSS 5.5
CVE-2023-27961
MEDIUM
iPadOS < 15.7.4 - Information Exfiltration via Malicious Calendar Invitation
CVSS 5.5
CVE-2023-31039
CRITICAL
Apache bRPC < 1.5.0 - Remote Code Execution via ServerOptions pid_file Parameter
CVSS 9.8
CVE-2023-31047
CRITICAL
Django <3.2.19, <4.1.9, <4.2.1 - Auth Bypass
CVSS 9.8
CVE-2023-30434
MEDIUM
IBM Storage Scale and Elastic Storage System - Denial of Service via Kernel Panic
CVSS 6.2
CVE-2023-21504
MEDIUM
Samsung Android Shannon Baseband - Buffer Overflow in mm_Plmncoordination.c
CVSS 5.6
CVE-2023-21503
MEDIUM
Samsung Android Shannon Baseband - Buffer Overflow in mm_LteInterRatManagement.c
CVSS 5.6
CVE-2023-21502
MEDIUM
Samsung Android - Privilege Escalation via FactoryTest Debugging Commands
CVSS 5.7
Details
Vulnerabilities
12,467
Exploit Likelihood
High