The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,468 vulnerabilities with CWE-20
CVE-2021-4219
MEDIUM
ImageMagick < 6.9.12-9 - Denial of Service via Improper File Handling
CVSS 5.5
CVE-2021-27420
MEDIUM
GE Multilin UR Series Firmware < 8.10 - Denial of Service via Unsupported HTTP Verb Handling
CVSS 5.3
CVE-2021-27418
MEDIUM
GE Multilin UR Firmware < 8.10 - Cross-Site Scripting via Improper Input Validation
CVSS 5.3
CVE-2021-44040
HIGH
Apache Traffic Server 8.0.0-8.1.3 and 9.0.0-9.1.1 - Improper Input Validation in Request Line Parsing
CVSS 7.5
CVE-2021-39701
HIGH
Android 11-12 - Local Privilege Escalation via ControlsProviderLifecycleManager ServiceConnection
CVSS 7.8
CVE-2021-38910
MEDIUM
IBM DataPower Gateway V10CD-2108.4.1 - Auth Bypass
CVSS 5.3
CVE-2021-42857
MEDIUM
Riverbed SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal via AgentDaServlet API
CVSS 5.3
CVE-2021-42856
MEDIUM
Riverbed SteelCentral AppInternals Dynamic Sampling Agent - Reflected XSS via DsaDataTest Metric Parameter
CVSS 4.7
CVE-2021-42854
CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal via PluginServlet API
CVSS 9.8
CVE-2021-42853
CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal via AgentDiagnosticServlet Logs API
CVSS 9.1
CVE-2021-42787
CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Path Traversal and Arbitrary File Write
CVSS 9.4
CVE-2021-42786
CRITICAL
SteelCentral AppInternals Dynamic Sampling Agent 11.0.0-11.8.7 - Remote Code Execution via API Request Injection
CVSS 9.8
CVE-2021-20302
MEDIUM
OpenEXR - Denial of Service via TiledInputFile Floating-Point Exception
CVSS 5.5
CVE-2021-23192
HIGH
Samba 4.10.0-4.13.13 - DCE/RPC Request Fragment Signature Bypass
CVSS 7.5
CVE-2021-32586
HIGH
FortiMail < 7.0.1 - Unauthenticated Environment Variable Injection via Web Server CGI
CVSS 7.7
CVE-2021-26617
HIGH
firstmall - Remote Code Execution via navercheckout_add Function
CVSS 8.1
CVE-2021-26618
HIGH
ToOffice < 3.15.6 - Arbitrary File Creation via ToWord Input Validation
CVSS 7.1
CVE-2021-4120
HIGH
snapd < 2.54.3 - AppArmor Policy Rule Injection via Malformed Content Interface and Layout Declarations
CVSS 8.2
CVE-2021-3781
CRITICAL
Ghostscript - Command Execution via SAFER Sandbox Escape
CVSS 9.9
CVE-2021-39676
HIGH
Android 11 - Local Privilege Escalation via Parcel Deserialization Mismatch
CVSS 7.8
CVE-2021-22800
HIGH
Modicon M218 Logic Controller <5.1.0.6 - DoS
CVSS 7.5
CVE-2021-22787
HIGH
Schneider Electric Modicon M340 BMXP34 < V3.40 & X80 - DoS via Crafted HTTP Request
CVSS 7.5
CVE-2021-44454
HIGH
Intel Quartus Prime Pro Edition < 21.3 - Authenticated Privilege Escalation via Third-Party Component
CVSS 7.8
CVE-2021-33155
MEDIUM
Intel(R) Wireless Bluetooth(R) & Killer(TM) Bluetooth(R) <22.100 - DoS
CVSS 5.7
CVE-2021-33115
HIGH
Intel(R) PROSet/Wireless WiFi - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
12,468
Exploit Likelihood
High