The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,467 vulnerabilities with CWE-20
CVE-2023-21431
LOW
Bixby Vision < 3.7.70.17 - Unauthenticated Data Access via Improper Input Validation
CVSS 3.3
CVE-2023-21428
MEDIUM
Samsung Android TelephonyUI - Improper Input Validation
CVSS 4.0
CVE-2023-0751
MEDIUM
FreeBSD - Improper Input Validation in GELI Key File Handling
CVSS 6.5
CVE-2023-0615
MEDIUM
Linux Kernel - Memory Leak and Integer Overflow in V4L2 vivid Test Code via VIDIOC_S_DV_TIMINGS ioctl
CVSS 5.5
CVE-2023-20613
MEDIUM
Android - Local Privilege Escalation via Missing Bounds Check in ril
CVSS 6.7
CVE-2023-20612
MEDIUM
Android - Local Privilege Escalation via Missing Bounds Check in ril
CVSS 6.7
CVE-2023-20606
MEDIUM
Android - Out-of-bounds Read in apusys
CVSS 4.4
CVE-2023-24493
MEDIUM
Tenable.sc < 5.23.1 - Authenticated Formula Injection via Report Export
CVSS 5.7
CVE-2023-0284
MEDIUM
Tribe29 Checkmk <2.1.0p19, <2.0.0p32, <=1.6.0 - Info Disclosure
CVSS 6.8
CVE-2023-0229
MEDIUM
github.com/openshift/apiserver-library-go - Privilege Escalation
CVSS 6.3
CVE-2023-23560
CRITICAL
Lexmark B2236/B2338/B2442/B2546/B2650/B2865/B3340/B3442/C2240/C2325/C2326/C2425/C2535/C3224/C3326 Firmware SSRF
CVSS 9.8
CVE-2023-0434
HIGH
pyload < 0.5.0b3.dev40 - Improper Input Validation
CVSS 7.5
CVE-2023-20045
MEDIUM
Cisco Small Business RV160-260 - RCE
CVSS 4.9
CVE-2023-20026
MEDIUM
Cisco Small Business RV016-325 - Command Injection
CVSS 6.5
CVE-2023-20020
HIGH
Cisco BroadWorks 22.0-23.0.1075 Unauthenticated DoS via HTTP Request Parsing
CVSS 8.6
CVE-2023-21607
HIGH
Adobe Acrobat Reader <22.003.20282 - RCE
CVSS 7.8
CVE-2023-22734
MEDIUM
Shopware < 6.4.18.1 - Newsletter Double Opt-In Bypass
CVSS 4.3
CVE-2023-22730
MEDIUM
Shopware < 6.4.18.1 - Cart Validator Bypass via Duplicate Line Item
CVSS 5.3
CVE-2023-0299
CRITICAL
publify/publify <9.2.10 - Info Disclosure
CVSS 9.8
CVE-2023-22496
HIGH
netdata < 1.37.0 - Remote Code Execution via Crafted Registry Hostname in Streaming Alert
CVSS 8.1
CVE-2023-22470
LOW
Nextcloud Deck < 1.6.5 - Denial of Service via Database Error
CVSS 3.5
CVE-2023-21596
HIGH
Adobe InCopy <= 17.4 and 18.0 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-21588
HIGH
Adobe InDesign <= 17.4 and 18.0 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2023-22491
HIGH
gatsby-transformer-remark <5.25.1 and 6.0.0-6.3.2 - JavaScript Injection via gray-matter Frontmatter Processing
CVSS 8.1
CVE-2023-22952
HIGH
KEV
SugarCRM unauthenticated Remote Code Execution (RCE)
CVSS 8.8
Details
Vulnerabilities
12,467
Exploit Likelihood
High