The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,440 vulnerabilities with CWE-20
CVE-2025-57805
HIGH
Scratch Channel <1.1 - Info Disclosure
CVE-2025-55301
MEDIUM
Scratch Channel <1 - Info Disclosure
CVSS 6.7
CVE-2025-52451
HIGH
Tableau Server < 2023.3.19 - Absolute Path Traversal via tabdoc API Create-Data-Source-From-File-Upload
CVSS 8.5
CVE-2025-50674
HIGH
OpenMediaVault 7.4.17 - Privilege Escalation
CVSS 7.8
CVE-2025-9288
CRITICAL
sha.js < 2.4.11 - Input Data Manipulation via Improper Input Validation
CVSS 9.1
CVE-2025-9287
CRITICAL
cipher-base <1.0.4 - Info Disclosure
CVSS 9.1
CVE-2025-55444
CRITICAL
Online Artwork & Fine Arts MCA Project 1.0 - SQL Injection
CVSS 9.8
CVE-2025-36114
MEDIUM
IBM QRadar SOAR Plugin App 1.0.0-5.6.0 - Path Traversal via URL Request
CVSS 6.5
CVE-2025-7693
CRITICAL
Rockwell Automation PLC - Micro850 L50E V20.011-V22.011 - Denial of Service via Malformed CIP Forward Close Packet
CVE-2025-6625
HIGH
Schneider Electric Modicon M340 - Denial of Service via Crafted FTP Command
CVSS 7.5
CVE-2025-52620
MEDIUM
HCL BigFix SaaS < 8.1.14 - Cross-Site Scripting via Image Upload
CVSS 4.3
CVE-2025-9060
CRITICAL
MSoft MFlash 8.0 - Authenticated Remote Code Execution via Integration Configuration
CVSS 9.1
CVE-2025-7507
MEDIUM
elink - Embed Content <= 1.1.0 - Authenticated Malicious Redirect via Shortcode URL Parameter
CVSS 6.4
CVE-2025-20148
HIGH
Cisco Secure Firewall Management Center - XSS
CVSS 8.5
CVE-2025-8876
HIGH
KEV
N-able N-central < 2025.3.1 - OS Command Injection
CVSS 8.8
CVE-2025-7971
HIGH
Studio 5000 Logix Designer - Code Injection
CVE-2025-8963
MEDIUM
jeecgboot JimuReport < 2.1.1 - Deserialization of Untrusted Data via Data Large Screen Template
CVSS 6.3
CVE-2025-27388
HIGH
OPPO Health App <= 4.23.4 - WebView Arbitrary URL Token Theft
CVE-2025-4410
HIGH
InsydeH2O - Buffer Overflow in SetupUtility
CVSS 7.5
CVE-2025-4277
HIGH
InsydeH2O Kernel 5.2-5.7 - Arbitrary Memory Write and Code Execution in SMRAM via Tcg2Smm
CVSS 7.5
CVE-2025-4276
HIGH
InsydeH2O Kernel 5.3-5.7 - Arbitrary SMRAM Write and SMM Code Execution via UsbCoreDxe
CVSS 7.5
CVE-2025-49554
HIGH
Adobe Commerce < 2.4.4 - Denial of Service via Improper Input Validation
CVSS 7.5
CVE-2025-25005
MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 6.5
CVE-2025-32004
LOW
Intel Edger8r Tool - Privilege Escalation
CVSS 3.9
CVE-2025-27537
MEDIUM
Intel(R) Tiber(TM) Edge Platform <24.11.1 - Privilege Escalation
CVSS 5.5
Details
Vulnerabilities
12,440
Exploit Likelihood
High