CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,470 vulnerabilities with CWE-20
CVE-2021-25500 HIGH
HDCP LDFW <SMR Nov-2021 Release 1 - Code Injection
CVSS 7.2
CVE-2021-40127 MEDIUM
Cisco Small Business 200/300/500 Series Switches - Unauthenticated Denial of Service via HTTP Request
CVSS 5.3
CVE-2021-40120 MEDIUM
Cisco Small Business RV Series Routers - Authenticated OS Command Injection via Web Management Interface
CVSS 6.5
CVE-2021-34597 HIGH
Phoenix Contact PC Worx < 1.88 - Unauthenticated Arbitrary File Write via Project File
CVSS 7.8
CVE-2021-41585 HIGH
Apache Traffic Server 5.0.0-9.1.0 - Denial of Service via Socket Connection Handling
CVSS 7.5
CVE-2021-37149 HIGH
Apache Traffic Server 8.0.0-8.1.2 and 9.0.0-9.1.0 - HTTP Request Smuggling via Header Parsing
CVSS 7.5
CVE-2021-37148 HIGH
Apache Traffic Server 8.0.0-8.1.2 and 9.0.0-9.0.1 - HTTP Request Smuggling via Header Parsing
CVSS 7.5
CVE-2021-37147 HIGH
Apache Traffic Server 8.0.0-8.1.2 and 9.0.0-9.1.0 - HTTP Request Smuggling via Header Parsing
CVSS 7.5
CVE-2021-20707 HIGH
Transaction Server <4.3 - Info Disclosure
CVSS 7.5
CVE-2021-20706 HIGH
NEC CLUSTERPRO X and EXPRESSCLUSTER X < 4.3 - Remote File Upload via WebManager
CVSS 7.5
CVE-2021-20705 HIGH
NEC CLUSTERPRO X and EXPRESSCLUSTER X < 4.3 - Remote File Upload via WebManager
CVSS 7.5
CVE-2021-37996 MEDIUM
Google Chrome < 95.0.4638.54 - Navigation Restriction Bypass via Malicious File Download
CVSS 5.5
CVE-2021-25742 HIGH
ingress-nginx < 0.49.1 - Unauthenticated Secret Exposure via Custom Snippets
CVSS 7.6
CVE-2021-22491 HIGH
Huawei EMUI and Magic UI - Denial of Service via Input Validation Vulnerability
CVSS 7.5
CVE-2021-22467 MEDIUM
HarmonyOS - Unauthenticated Arbitrary Memory Read via Improper Input Validation
CVSS 5.5
CVE-2021-22457 LOW
HarmonyOS - Out-of-Bounds Write via Improper Input Validation
CVSS 3.3
CVE-2021-22452 MEDIUM
HarmonyOS - Improper Input Validation Leading to Arbitrary Memory Read
CVSS 5.5
CVE-2021-34791 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated NAT ALG Security Bypass
CVSS 4.7
CVE-2021-34790 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated NAT ALG Security Bypass
CVSS 4.7
CVE-2021-34783 HIGH
Cisco ASA/Firepower Threat Defense - Unauthenticated DoS via Crafted SSL/TLS Message
CVSS 8.6
CVE-2021-34756 MEDIUM
Cisco Firepower Management Center Virtual Appliance - Authenticated OS Command Injection
CVSS 6.7
CVE-2021-34755 MEDIUM
Cisco Firepower Management Center Virtual Appliance - Authenticated OS Command Injection
CVSS 6.7
CVE-2021-41173 MEDIUM
Go Ethereum <1.10.9 - Use After Free
CVSS 5.7
CVE-2021-26607 HIGH
NEXACRO17 < 17.1.3.301 - Remote Code Execution via execDefaultBrowser Method
CVSS 8.1
CVE-2021-41105 HIGH
FreeSWITCH < 1.10.7 - Unauthenticated Denial of Service via SRTP Packet Flood
CVSS 7.5
Details
Vulnerabilities 12,470
Exploit Likelihood High