CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,468 vulnerabilities with CWE-20
CVE-2021-4219 MEDIUM
ImageMagick < 6.9.12-9 - Denial of Service via Improper File Handling
CVSS 5.5
CVE-2021-27420 MEDIUM
GE Multilin UR Series Firmware < 8.10 - Denial of Service via Unsupported HTTP Verb Handling
CVSS 5.3
CVE-2021-27418 MEDIUM
GE Multilin UR Firmware < 8.10 - Cross-Site Scripting via Improper Input Validation
CVSS 5.3
CVE-2021-44040 HIGH
Apache Traffic Server 8.0.0-8.1.3 and 9.0.0-9.1.1 - Improper Input Validation in Request Line Parsing
CVSS 7.5
CVE-2021-39701 HIGH
Android 11-12 - Local Privilege Escalation via ControlsProviderLifecycleManager ServiceConnection
CVSS 7.8
CVE-2021-38910 MEDIUM
IBM DataPower Gateway V10CD-2108.4.1 - Auth Bypass
CVSS 5.3
CVE-2021-42857 MEDIUM
Riverbed SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal via AgentDaServlet API
CVSS 5.3
CVE-2021-42856 MEDIUM
Riverbed SteelCentral AppInternals Dynamic Sampling Agent - Reflected XSS via DsaDataTest Metric Parameter
CVSS 4.7
CVE-2021-42854 CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal via PluginServlet API
CVSS 9.8
CVE-2021-42853 CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal via AgentDiagnosticServlet Logs API
CVSS 9.1
CVE-2021-42787 CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal and Arbitrary File Write
CVSS 9.4
CVE-2021-42786 CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Remote Code Execution via API Request Injection
CVSS 9.8
CVE-2021-20302 MEDIUM
OpenEXR - Denial of Service via TiledInputFile Floating-Point Exception
CVSS 5.5
CVE-2021-23192 HIGH
Samba 4.10.0-4.13.13 - DCE/RPC Request Fragment Signature Bypass
CVSS 7.5
CVE-2021-32586 HIGH
FortiMail < 7.0.1 - Unauthenticated Environment Variable Injection via Web Server CGI
CVSS 7.7
CVE-2021-26617 HIGH
firstmall - Remote Code Execution via navercheckout_add Function
CVSS 8.1
CVE-2021-26618 HIGH
ToOffice < 3.15.6 - Arbitrary File Creation via ToWord Input Validation
CVSS 7.1
CVE-2021-4120 HIGH
snapd < 2.54.3 - AppArmor Policy Rule Injection via Malformed Content Interface and Layout Declarations
CVSS 8.2
CVE-2021-3781 CRITICAL
Ghostscript - Command Execution via SAFER Sandbox Escape
CVSS 9.9
CVE-2021-39676 HIGH
Android 11 - Local Privilege Escalation via Parcel Deserialization Mismatch
CVSS 7.8
CVE-2021-22800 HIGH
Modicon M218 Logic Controller <5.1.0.6 - DoS
CVSS 7.5
CVE-2021-22787 HIGH
Schneider Electric Modicon M340 BMXP34 < V3.40 & X80 - DoS via Crafted HTTP Request
CVSS 7.5
CVE-2021-44454 HIGH
Intel Quartus Prime Pro Edition < 21.3 - Authenticated Privilege Escalation via Third-Party Component
CVSS 7.8
CVE-2021-33155 MEDIUM
Intel(R) Wireless Bluetooth(R) & Killer(TM) Bluetooth(R) <22.100 - DoS
CVSS 5.7
CVE-2021-33115 HIGH
Intel(R) PROSet/Wireless WiFi - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 12,468
Exploit Likelihood High