The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,468 vulnerabilities with CWE-20
CVE-2021-30338
HIGH
Qualcomm Snapdragon Compute - Information Disclosure via TrustZone Memory Transfer
CVSS 7.1
CVE-2021-35531
MEDIUM
Hitachi Energy TXpert Hub CoreTec <2.2.1 - Command Injection
CVSS 6.7
CVE-2021-26631
HIGH
Mangboard commerce < 1.3.9 - Improper Input Validation in Order Amount Calculation
CVSS 8.0
CVE-2021-26630
HIGH
HANDY Groupware < 1.7.4.7 - Arbitrary File Download and Execution via ActiveX Module
CVSS 7.8
CVE-2021-33025
MEDIUM
xArrow SCADA <7.2 - Privilege Escalation
CVSS 5.6
CVE-2021-26351
MEDIUM
AMD Ryzen 3/5/7 Firmware - Denial of Service via Insufficient DRAM Address Validation
CVSS 5.5
CVE-2021-33108
MEDIUM
Intel(R) In-Band Manageability <2.13.0 - Privilege Escalation
CVSS 6.7
CVE-2021-0159
HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.8
CVE-2021-0154
HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.8
CVE-2021-0126
HIGH
Intel Manageability Commander < 2.2 - Authenticated Privilege Escalation via Adjacent Access
CVSS 8.0
CVE-2021-33316
CRITICAL
TRENDnet TI-PG1284i <2.0.2.S0 - Buffer Overflow
CVSS 9.8
CVE-2021-33315
CRITICAL
TRENDnet TI-PG1284i <2.0.2.S0 - Buffer Overflow
CVSS 9.8
CVE-2021-26373
MEDIUM
AMD EPYC 7002 Series Firmware < romepi-sp3_1.0.0.d - Denial of Service via SMU Voltage Mismanagement
CVSS 5.5
CVE-2021-46771
HIGH
AMD EPYC Milan Firmware < milanpi-sp3_1.0.0.4 - Arbitrary Code Execution via ASP System Call
CVSS 7.8
CVE-2021-26370
HIGH
AMD EPYC 7003 Firmware < 1.0.0.4 - Arbitrary Bootloader Memory Overwrite via SVC_LOAD_FW_IMAGE_BY_INSTANCE
CVSS 7.1
CVE-2021-27760
MEDIUM
Notes 11.0-11.0.1 FP4 - Authenticated RCE
CVSS 4.6
CVE-2021-25746
HIGH
ingress-nginx < 1.2.0 - Unauthenticated Credential Exposure via Ingress Annotations
CVSS 7.6
CVE-2021-25745
HIGH
ingress-nginx < 1.2.0 - Authenticated Credential Exposure via Ingress Path Field
CVSS 7.6
CVE-2021-41945
CRITICAL
httpx < 0.23.0 - Improper Input Validation in URL.copy_with
CVSS 9.1
CVE-2021-4212
MEDIUM
Lenovo Notebook - Privilege Escalation
CVSS 6.7
CVE-2021-4211
MEDIUM
Lenovo Desktop/ThinkStation/ThinkEdge - Local Privilege Escalation
CVSS 6.7
CVE-2021-4210
MEDIUM
Lenovo Desktop/ThinkStation/ThinkEdge - Local Privilege Escalation
CVSS 6.7
CVE-2021-3970
MEDIUM
Lenovo IdeaPad 3 Firmware - Authenticated Arbitrary Code Execution via LenovoVariable SMI Handler
CVSS 6.7
CVE-2021-26626
HIGH
XPLATFORM < 9.2.2.280 - Remote Code Execution via execBrowser Method
CVSS 8.1
CVE-2021-3624
HIGH
dcraw - Integer Overflow via Malicious X3F Input Image
CVSS 7.8
Details
Vulnerabilities
12,468
Exploit Likelihood
High