CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,472 vulnerabilities with CWE-20
CVE-2021-25444 MEDIUM
keymaster <SMR AUG-2021 Release 1 - Info Disclosure
CVSS 5.5
CVE-2021-1602 HIGH
Cisco Small Business RV Series Router Firmware < 1.0.01.04 - Unauthenticated OS Command Injection via Web Interface
CVSS 8.2
CVE-2021-30589 MEDIUM
Google Chrome <92.0.4515.107 - CSRF
CVSS 4.3
CVE-2021-22400 MEDIUM
Huawei Smartphones - Code Injection
CVSS 5.5
CVE-2021-37914 MEDIUM
Argo Workflows < 3.1.3 and 3.1.0-3.1.6 - Unauthenticated Workflow Disruption via Expression Template Injection
CVSS 6.5
CVE-2021-3673 HIGH
radare2 5.3.1 - Denial of Service via Crafted LE Binary
CVSS 7.5
CVE-2021-33196 HIGH
Go <1.15.13, <1.16.5 - Buffer Overflow
CVSS 7.5
CVE-2021-22445 HIGH
Huawei Smartphone - Info Disclosure
CVSS 7.5
CVE-2021-22444 CRITICAL
Huawei EMUI and Magic UI - Remote Code Execution via Input Verification Vulnerability
CVSS 9.8
CVE-2021-22443 HIGH
Huawei Smartphone - Memory Corruption
CVSS 7.5
CVE-2021-22397 MEDIUM
Huawei ManageOne 8.0.0 - Privilege Escalation
CVSS 6.7
CVE-2021-22381 HIGH
Huawei EMUI and Magic UI - Denial of Service via Input Verification Vulnerability
CVSS 7.5
CVE-2021-33527 CRITICAL
MB connect line mbDIALUP <= 3.9R0.0 - RCE
CVSS 9.8
CVE-2021-29298 MEDIUM
Emerson GE Automation Proficy Machine Edition v8.0 - Denial of Service via Crafted Traffic to FrameworX.exe
CVSS 5.3
CVE-2021-37595 CRITICAL
FreeRDP < 2.4.0 - Improper Input Validation in wf_cliprdr_server_file_contents_request
CVSS 9.8
CVE-2021-37594 CRITICAL
FreeRDP < 2.4.0 - Improper Input Validation in wf_cliprdr_server_file_contents_request
CVSS 9.8
CVE-2021-36742 HIGH KEV
Trend Micro Apex One/OfficeScan XG/Worry-Free Business Security - Local Privilege Escalation
CVSS 7.8
CVE-2021-34432 HIGH
Eclipse Mosquitto < 2.0.7 - Denial of Service via Zero-Length Topic PUBLISH Packet
CVSS 7.5
CVE-2021-32795 MEDIUM
ArchiSteamFarm < 4.3.1.0 - Unauthenticated Denial of Service via Steam Chat Message
CVSS 6.5
CVE-2021-29770 MEDIUM
IBM i2 Analyze 4.3.0-4.3.2 - Authenticated Unauthorized Action via Hazardous Input Validation
CVSS 6.5
CVE-2021-1097 HIGH
NVIDIA vGPU <12.3-11.5-8.8 - Info Disclosure
CVSS 7.8
CVE-2021-29780 MEDIUM
IBM Resilient SOAR < 41.1 - Authenticated Privilege Escalation via Input Validation
CVSS 4.7
CVE-2021-33592 CRITICAL
NAVER Toolbar < 4.0.30.323 - Remote Code Execution via Crafted upgrade.xml File
CVSS 9.8
CVE-2021-3452 MEDIUM
Lenovo BIOS - Authenticated Arbitrary Code Execution via System Shutdown SMI Callback
CVSS 6.7
CVE-2021-36758 MEDIUM
1Password Connect < 1.2 - Privilege Escalation via Secrets Automation Access Token
CVSS 5.4
Details
Vulnerabilities 12,472
Exploit Likelihood High