CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,470 vulnerabilities with CWE-20
CVE-2021-26323 HIGH
AMD EPYC Firmware - Memory Integrity Impact via SEV Command Validation Failure
CVSS 7.8
CVE-2021-26321 MEDIUM
AMD EPYC 7001 Series Firmware - Authenticated Denial of Service via SEV ID Command Validation
CVSS 5.5
CVE-2021-42114 CRITICAL
Samsung DDR4 SDRAM Firmware - Rowhammer Bit Flip via Non-Uniform Access Patterns
CVSS 9.0
CVE-2021-36325 HIGH
Dell Alienware BIOS < 1.15.1 Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2021-36324 HIGH
Dell Alienware BIOS < 1.15.1 - Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2021-36323 HIGH
Dell Alienware BIOS < 1.15.1 - Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2021-3843 MEDIUM
Lenovo ThinkPad Firmware - Authenticated Arbitrary Code Execution via SMI EEPROM Access
CVSS 6.7
CVE-2021-3786 MEDIUM
Lenovo Notebook/ThinkPad - Info Disclosure
CVSS 4.4
CVE-2021-3719 MEDIUM
ThinkCentre/ThinkStation - Privilege Escalation
CVSS 6.7
CVE-2021-3599 MEDIUM
Lenovo ThinkPad Firmware - Authenticated Arbitrary Code Execution via SMI Callback Function
CVSS 6.7
CVE-2021-38985 MEDIUM
IBM Tivoli Key Lifecycle Manager <4.2 - Info Disclosure
CVSS 4.3
CVE-2021-38973 LOW
IBM Tivoli Key Lifecycle Manager <4.2 - Info Disclosure
CVSS 2.7
CVE-2021-38972 MEDIUM
IBM Tivoli Key Lifecycle Manager <4.2 - Info Disclosure
CVSS 4.3
CVE-2021-30254 HIGH
Qualcomm APQ8009 and related firmware - Buffer Overflow via Factory Calibration DIAG Command
CVSS 7.8
CVE-2021-34417 HIGH
Zoom On-Premise Meeting Connector < 4.6.365.20210703 - Remote Command Injection
CVSS 7.9
CVE-2021-3911 MEDIUM
cloudflare/octorpki < 1.3.0 - Denial of Service via ROA IP Address Bit Overflow
CVSS 4.2
CVE-2021-3910 MEDIUM
cloudflare/octorpki < 1.3.0 - Denial of Service via Invalid ROA Handling
CVSS 4.4
CVE-2021-3907 HIGH
OctoRPKI < 1.3.0 - Path Traversal and Remote Code Execution via Unsanitized URI Filename
CVSS 7.4
CVE-2021-3572 MEDIUM
pip < 21.1 - Remote Revision Manipulation via Unicode Separator Handling
CVSS 5.7
CVE-2021-41772 HIGH
GO < 1.16.10 - Improper Input Validation
CVSS 7.5
CVE-2021-41250 MEDIUM
pythondiscord/bot < 67390298852513d13e0213870e50fb3cff1424e0 - Moderation Filter Bypass via URL Inclusion
CVSS 4.3
CVE-2021-43406 HIGH
FusionPBX <4.5.30 - Info Disclosure
CVSS 8.8
CVE-2021-25509 MEDIUM
Samsung Flow <4.8.5.0 - Path Traversal
CVSS 5.9
CVE-2021-25504 MEDIUM
Group Sharing <10.8.03.2 - Info Disclosure
CVSS 4.0
CVE-2021-25503 MEDIUM
Android - Remote Code Execution via HDCP Input Validation
CVSS 5.0
Details
Vulnerabilities 12,470
Exploit Likelihood High