The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,467 vulnerabilities with CWE-20
CVE-2023-28100
CRITICAL
flatpak < 1.10.8 - Command Injection via TIOCLINUX ioctl
CVSS 10.0
CVE-2023-24571
HIGH
Dell Embedded Box PC 3000 Firmware < 1.18.0 - Authenticated Arbitrary Code Execution
CVSS 7.5
CVE-2023-28099
MEDIUM
OpenSIPS < 3.1.9 - Denial of Service via ds_is_in_list() Invalid IP Address Handling
CVSS 5.9
CVE-2023-28098
MEDIUM
OpenSIPS < 3.1.7 - Denial of Service via Crafted Authorization Header
CVSS 5.9
CVE-2023-28095
HIGH
OpenSIPS < 3.1.7 - Denial of Service via build_res_buf_from_sip_req Function
CVSS 7.5
CVE-2023-27601
HIGH
OpenSIPS < 3.1.7 - Denial of Service via Malformed SDP Body in sipmsgops Module
CVSS 7.5
CVE-2023-27600
HIGH
OpenSIPS < 3.1.7 - Denial of Service via Malformed SDP Body in sipmsgops Module
CVSS 7.5
CVE-2023-27599
HIGH
OpenSIPS < 3.1.7 - Denial of Service via Malformed To Header in append_hf Function
CVSS 7.5
CVE-2023-27597
HIGH
OpenSIPS < 3.1.8 - Denial of Service via Crafted SIP Message in rewrite_ruri Function
CVSS 7.5
CVE-2023-0100
HIGH
Eclipse BIRT 2.6.2-4.13.0 - Server-Side Request Forgery via Report Parameter
CVSS 8.8
CVE-2023-24866
MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
CVE-2023-24865
MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
CVE-2023-24856
HIGH
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 7.5
CVE-2023-23419
HIGH
Windows 11 22H2 < 10.0.22000.1413 - Elevation of Privilege in ReFS
CVSS 7.8
CVE-2023-23416
HIGH
Windows Cryptographic Services - Remote Code Execution
CVSS 7.8
CVE-2023-23409
MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure in Client Server Run-Time Subsystem
CVSS 5.5
CVE-2023-23397
CRITICAL
KEV
Microsoft Outlook - Privilege Escalation
CVSS 9.8
CVE-2023-24579
MEDIUM
McAfee Total Protection <16.0.51 - Info Disclosure
CVSS 5.5
CVE-2023-24033
HIGH
Samsung Exynos Modem 5123, 5300, 980, 1080, and Auto T5123 Firmware - Denial of Service via SDP Format Type Mismatch
CVSS 7.5
CVE-2023-24975
MEDIUM
IBM Spectrum Symphony 7.3 - HTTP Header Injection via HOST Header
CVSS 5.4
CVE-2023-25947
MEDIUM
OpenHarmony 3.1-3.1.4 - Denial of Service via Malicious HAP Package Installation
CVSS 6.2
CVE-2023-24465
MEDIUM
OpenHarmony - Null Pointer Reference
CVSS 5.5
CVE-2023-22301
MEDIUM
OpenHarmony <v3.1.5 - Memory Corruption
CVSS 6.5
CVE-2023-27484
MEDIUM
crossplane 1.9.0-1.9.1 - Uncontrolled Resource Consumption via High Index in Composition Patch
CVSS 6.2
CVE-2023-27483
MEDIUM
crossplane-runtime 0.17.0-0.19.1 - Uncontrolled Resource Consumption via Paved.SetValue Method
CVSS 5.9
Details
Vulnerabilities
12,467
Exploit Likelihood
High