The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,468 vulnerabilities with CWE-20
CVE-2021-44694
MEDIUM
SIMATIC S7-1200 CPU and S7-PLCSIM Advanced Firmware - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 5.5
CVE-2021-40365
HIGH
Siemens SIMATIC S7-1200 and ET 200 SP Open Controller - Denial of Service via Crafted Packets
CVSS 7.5
CVE-2021-37533
MEDIUM
Apache Commons Net < 3.9.0 - Information Disclosure via FTP PASV Host Redirection
CVSS 6.5
CVE-2021-26251
MEDIUM
Intel Distribution of OpenVINO Toolkit < 2021.4.2 - Authenticated Denial of Service via Network Access
CVSS 5.3
CVE-2021-0185
HIGH
Intel(R) Server Board M10JNP <7.216 - Privilege Escalation
CVSS 7.5
CVE-2021-44769
MEDIUM
Lanner Inc IAC-AST2500A Firmware 1.10.0 - Denial of Service via TLS Certificate Generation
CVSS 4.9
CVE-2021-27774
LOW
HCL Digital Experience - Information Exposure via Error Response
CVSS 3.1
CVE-2021-40017
CRITICAL
Huawei EMUI - Out-of-Bounds Memory Access in HW_KEYMASTER Module
CVSS 9.8
CVE-2021-40648
MEDIUM
man2html 1.6g - Use-After-Free via Chunk Metadata Manipulation
CVSS 5.5
CVE-2021-35122
CRITICAL
Qualcomm AQT1000 Firmware - Improper Input Validation
CVSS 9.3
CVE-2021-35109
MEDIUM
Snapdragon Connectivity - Buffer Overflow
CVSS 6.8
CVE-2021-3754
MEDIUM
Keycloak - Improper Input Validation in Username Registration
CVSS 5.3
CVE-2021-4204
HIGH
Linux Kernel < 5.8.0 - Out-of-Bounds Memory Access in eBPF
CVSS 7.1
CVE-2021-4125
HIGH
OpenShift 4.6.0-4.6.51 - Deserialization of Untrusted Data in Metering Hive Container
CVSS 8.1
CVE-2021-4041
HIGH
ansible-runner < 2.1.0 - Command Injection via Improper Shell Command Escaping
CVSS 7.8
CVE-2021-3442
MEDIUM
Red Hat OpenShift API Management - Authenticated Stored Cross-Site Scripting
CVSS 5.4
CVE-2021-44545
MEDIUM
Intel Killer AC 1550 Firmware < 3.1122.1105 - Unauthenticated Denial of Service via Adjacent Access
CVSS 6.5
CVE-2021-26639
HIGH
WISA Smart Wing CMS < r18715.20211229 - Unauthenticated Arbitrary File Read via Input Validation Bypass
CVSS 8.1
CVE-2021-22289
HIGH
B&R Automation Studio >=4.0 - Unauthenticated Remote Code Execution via Project Upload Mechanism
CVSS 8.3
CVE-2021-37150
HIGH
Apache Traffic Server 8.0.0-9.1.2 - Improper Input Validation in Header Parsing
CVSS 7.5
CVE-2021-44221
HIGH
SIMATIC eaSie Core Package < 22.00 - Denial of Service via Message Passing Framework
CVSS 7.5
CVE-2021-3675
MEDIUM
Synaptics Fingerprint Driver < 5.1.340.26 - Authenticated Heap Tag Overwrite via Improper Input Validation
CVSS 5.5
CVE-2021-35116
HIGH
Qualcomm APQ8009 and related firmware - Remote Code Execution via Crafted Model Loading
CVSS 7.7
CVE-2021-35111
HIGH
Snapdragon Connectivity - Info Disclosure
CVSS 7.5
CVE-2021-35092
MEDIUM
Snapdragon Auto - Memory Corruption
CVSS 6.7
Details
Vulnerabilities
12,468
Exploit Likelihood
High