The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,470 vulnerabilities with CWE-20
CVE-2021-25500
HIGH
HDCP LDFW <SMR Nov-2021 Release 1 - Code Injection
CVSS 7.2
CVE-2021-40127
MEDIUM
Cisco Small Business 200/300/500 Series Switches - Unauthenticated Denial of Service via HTTP Request
CVSS 5.3
CVE-2021-40120
MEDIUM
Cisco Small Business RV Series Routers - Authenticated OS Command Injection via Web Management Interface
CVSS 6.5
CVE-2021-34597
HIGH
Phoenix Contact PC Worx < 1.88 - Unauthenticated Arbitrary File Write via Project File
CVSS 7.8
CVE-2021-41585
HIGH
Apache Traffic Server 5.0.0-9.1.0 - Denial of Service via Socket Connection Handling
CVSS 7.5
CVE-2021-37149
HIGH
Apache Traffic Server 8.0.0-8.1.2 and 9.0.0-9.1.0 - HTTP Request Smuggling via Header Parsing
CVSS 7.5
CVE-2021-37148
HIGH
Apache Traffic Server 8.0.0-8.1.2 and 9.0.0-9.0.1 - HTTP Request Smuggling via Header Parsing
CVSS 7.5
CVE-2021-37147
HIGH
Apache Traffic Server 8.0.0-8.1.2 and 9.0.0-9.1.0 - HTTP Request Smuggling via Header Parsing
CVSS 7.5
CVE-2021-20707
HIGH
Transaction Server <4.3 - Info Disclosure
CVSS 7.5
CVE-2021-20706
HIGH
NEC CLUSTERPRO X and EXPRESSCLUSTER X < 4.3 - Remote File Upload via WebManager
CVSS 7.5
CVE-2021-20705
HIGH
NEC CLUSTERPRO X and EXPRESSCLUSTER X < 4.3 - Remote File Upload via WebManager
CVSS 7.5
CVE-2021-37996
MEDIUM
Google Chrome < 95.0.4638.54 - Navigation Restriction Bypass via Malicious File Download
CVSS 5.5
CVE-2021-25742
HIGH
ingress-nginx < 0.49.1 - Unauthenticated Secret Exposure via Custom Snippets
CVSS 7.6
CVE-2021-22491
HIGH
Huawei EMUI and Magic UI - Denial of Service via Input Validation Vulnerability
CVSS 7.5
CVE-2021-22467
MEDIUM
HarmonyOS - Unauthenticated Arbitrary Memory Read via Improper Input Validation
CVSS 5.5
CVE-2021-22457
LOW
HarmonyOS - Out-of-Bounds Write via Improper Input Validation
CVSS 3.3
CVE-2021-22452
MEDIUM
HarmonyOS - Improper Input Validation Leading to Arbitrary Memory Read
CVSS 5.5
CVE-2021-34791
MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated NAT ALG Security Bypass
CVSS 4.7
CVE-2021-34790
MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated NAT ALG Security Bypass
CVSS 4.7
CVE-2021-34783
HIGH
Cisco ASA/Firepower Threat Defense - Unauthenticated DoS via Crafted SSL/TLS Message
CVSS 8.6
CVE-2021-34756
MEDIUM
Cisco Firepower Management Center Virtual Appliance - Authenticated OS Command Injection
CVSS 6.7
CVE-2021-34755
MEDIUM
Cisco Firepower Management Center Virtual Appliance - Authenticated OS Command Injection
CVSS 6.7
CVE-2021-41173
MEDIUM
Go Ethereum <1.10.9 - Use After Free
CVSS 5.7
CVE-2021-26607
HIGH
NEXACRO17 < 17.1.3.301 - Remote Code Execution via execDefaultBrowser Method
CVSS 8.1
CVE-2021-41105
HIGH
FreeSWITCH < 1.10.7 - Unauthenticated Denial of Service via SRTP Packet Flood
CVSS 7.5
Details
Vulnerabilities
12,470
Exploit Likelihood
High