CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,468 vulnerabilities with CWE-20
CVE-2021-44694 MEDIUM
SIMATIC S7-1200 CPU and S7-PLCSIM Advanced Firmware - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 5.5
CVE-2021-40365 HIGH
Siemens SIMATIC S7-1200 and ET 200 SP Open Controller - Denial of Service via Crafted Packets
CVSS 7.5
CVE-2021-37533 MEDIUM
Apache Commons Net < 3.9.0 - Information Disclosure via FTP PASV Host Redirection
CVSS 6.5
CVE-2021-26251 MEDIUM
Intel Distribution of OpenVINO Toolkit < 2021.4.2 - Authenticated Denial of Service via Network Access
CVSS 5.3
CVE-2021-0185 HIGH
Intel(R) Server Board M10JNP <7.216 - Privilege Escalation
CVSS 7.5
CVE-2021-44769 MEDIUM
Lanner Inc IAC-AST2500A Firmware 1.10.0 - Denial of Service via TLS Certificate Generation
CVSS 4.9
CVE-2021-27774 LOW
HCL Digital Experience - Information Exposure via Error Response
CVSS 3.1
CVE-2021-40017 CRITICAL
Huawei EMUI - Out-of-Bounds Memory Access in HW_KEYMASTER Module
CVSS 9.8
CVE-2021-40648 MEDIUM
man2html 1.6g - Use-After-Free via Chunk Metadata Manipulation
CVSS 5.5
CVE-2021-35122 CRITICAL
Qualcomm AQT1000 Firmware - Improper Input Validation
CVSS 9.3
CVE-2021-35109 MEDIUM
Snapdragon Connectivity - Buffer Overflow
CVSS 6.8
CVE-2021-3754 MEDIUM
Keycloak - Improper Input Validation in Username Registration
CVSS 5.3
CVE-2021-4204 HIGH
Linux Kernel < 5.8.0 - Out-of-Bounds Memory Access in eBPF
CVSS 7.1
CVE-2021-4125 HIGH
OpenShift 4.6.0-4.6.51 - Deserialization of Untrusted Data in Metering Hive Container
CVSS 8.1
CVE-2021-4041 HIGH
ansible-runner < 2.1.0 - Command Injection via Improper Shell Command Escaping
CVSS 7.8
CVE-2021-3442 MEDIUM
Red Hat OpenShift API Management - Authenticated Stored Cross-Site Scripting
CVSS 5.4
CVE-2021-44545 MEDIUM
Intel Killer AC 1550 Firmware < 3.1122.1105 - Unauthenticated Denial of Service via Adjacent Access
CVSS 6.5
CVE-2021-26639 HIGH
WISA Smart Wing CMS < r18715.20211229 - Unauthenticated Arbitrary File Read via Input Validation Bypass
CVSS 8.1
CVE-2021-22289 HIGH
B&R Automation Studio >=4.0 - Unauthenticated Remote Code Execution via Project Upload Mechanism
CVSS 8.3
CVE-2021-37150 HIGH
Apache Traffic Server 8.0.0-9.1.2 - Improper Input Validation in Header Parsing
CVSS 7.5
CVE-2021-44221 HIGH
SIMATIC eaSie Core Package < 22.00 - Denial of Service via Message Passing Framework
CVSS 7.5
CVE-2021-3675 MEDIUM
Synaptics Fingerprint Driver < 5.1.340.26 - Authenticated Heap Tag Overwrite via Improper Input Validation
CVSS 5.5
CVE-2021-35116 HIGH
Qualcomm APQ8009 and related firmware - Remote Code Execution via Crafted Model Loading
CVSS 7.7
CVE-2021-35111 HIGH
Snapdragon Connectivity - Info Disclosure
CVSS 7.5
CVE-2021-35092 MEDIUM
Snapdragon Auto - Memory Corruption
CVSS 6.7
Details
Vulnerabilities 12,468
Exploit Likelihood High