CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,470 vulnerabilities with CWE-20
CVE-2021-25471 LOW
Security Mode Command <SMR Oct-2021 Release 1 - DoS
CVSS 3.7
CVE-2021-25468 MEDIUM
Widevine trustlet <SMR Oct-2021 Release 1 - Memory Corruption
CVSS 4.4
CVE-2021-41114 MEDIUM
TYPO3 11.0.0-11.5.0 - Host Header Spoofing via trustedHostsPattern Regression
CVSS 4.8
CVE-2021-21705 MEDIUM
PHP 7.3.0-7.3.28 - Improper Input Validation in filter_var URL Validation
CVSS 4.3
CVE-2021-28547 HIGH
Adobe Creative Cloud Desktop Application < 5.3 - Privilege Escalation via OOBE Directory Deletion
CVSS 7.8
CVE-2021-36283 HIGH
Dell BIOS - Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2021-40712 MEDIUM
Adobe Experience Manager <6.5.9.0 - DoS
CVSS 6.5
CVE-2021-34416 CRITICAL
Zoom Meeting Connector < 4.6.360.20210325 - Remote Command Injection via Network Address Settings
CVSS 9.8
CVE-2021-34414 HIGH
Zoom Meeting Connector < 4.6.348.20201217 - Authenticated Remote Command Injection via Network Proxy Configuration
CVSS 7.2
CVE-2021-34570 HIGH
Phoenix Contact PLCnext Control Devices < 2021.0.5 - Denial of Service via Crafted JSON Request
CVSS 7.5
CVE-2021-41583 MEDIUM
vpn-user-portal 2.3.2-2.3.13 - Authenticated Arbitrary File Read via QR Code Exec Interaction
CVSS 6.5
CVE-2021-34714 HIGH
Cisco FXOS 2.2-2.2.2.148, Firepower, IOS, IOS XE, IOS XR, NX-OS < 8.4(3.115) - DoS via UDLD Packet
CVSS 7.4
CVE-2021-3583 HIGH
Ansible Automation Platform - Code Injection via Template Injection
CVSS 7.1
CVE-2021-39230 HIGH
Butter < 1.5 - Improper Input Validation
CVSS 8.8
CVE-2021-41531 HIGH
NLnet Labs Routinator <0.10.0 - Buffer Overflow
CVSS 7.5
CVE-2021-25741 HIGH
Kubernetes < 1.19.14 - Unauthenticated Files or Directories Accessible via Subpath Volume Mounts
CVSS 8.8
CVE-2021-41380 MEDIUM
RealVNC Viewer 6.21.406 - Denial of Service via Crafted RFB Protocol Data
CVSS 6.5
CVE-2021-38304 HIGH
NI-PAL <20.0.0 - Privilege Escalation
CVSS 7.8
CVE-2021-30261 HIGH
Qualcomm APQ8009 and related firmware - Integer and Heap Overflow via Beacon Template Update Command
CVSS 8.4
CVE-2021-30260 HIGH
Qualcomm APQ8009 and other Snapdragon Firmware - Integer Overflow to Buffer Overflow via Extscan Hostlist Configuration
CVSS 8.4
CVE-2021-41079 HIGH
Apache Tomcat 8.5.0-8.5.63 9.0.0-M1-9.0.43 10.0.0-M1-10.0.2 - Denial of Service via TLS Packet Validation Bypass
CVSS 7.5
CVE-2021-37909 CRITICAL
TSSServiSignAdapter < 1.0.20.0316 - Unauthenticated Arbitrary Registry Write via WriteRegistry Function
CVSS 9.8
CVE-2021-23030 HIGH
F5 Big-ip Advanced Web Application Firewall < 12.1.6 - Improper Input Validation
CVSS 7.5
CVE-2021-23028 HIGH
F5 <16.0.1.2, 15.1.3.1, 14.1.4.2, 13.1.4 - DoS
CVSS 7.5
CVE-2021-23036 HIGH
F5 BIG-IP Advanced Web Application Firewall 16.0.0-16.0.1 - Denial of Service via ASM and DataSafe Profile Configuration
CVSS 7.5
Details
Vulnerabilities 12,470
Exploit Likelihood High