CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,451 vulnerabilities with CWE-20
CVE-2024-12401 MEDIUM
cert-manager < 1.12.14 - Denial of Service via PEM Data Processing
CVSS 4.4
CVE-2024-49087 MEDIUM
Windows 10/11, Server 2019/2022/2025 - Information Disclosure via Mobile Broadband Driver
CVSS 4.6
CVE-2024-49073 MEDIUM
Windows Mobile Broadband Driver - Elevation of Privilege via Improper Input Validation
CVSS 6.8
CVE-2024-49057 HIGH
Microsoft Defender for Endpoint < 1.0.7128.0101 - Spoofing
CVSS 8.1
CVE-2024-11737 CRITICAL
Schneider Electric Modicon M241/M251/M258/LMC058 - DoS & Confidentiality Loss via Modbus
CVSS 9.8
CVE-2024-55655 LOW
sigstore-python 2.0.0-3.6.0 - Improper Input Validation of Integration Time in v2 and v3 Bundles
CVE-2024-55653 MEDIUM
pwndoc <= 0.5.3 - Authenticated Denial of Service via Audit ID Handling
CVSS 6.5
CVE-2024-52831 LOW
Adobe Experience Manager < 6.5.22.0 and < 2024.11.0 - Security Feature Bypass via Improper Input Validation
CVSS 3.5
CVE-2024-43755 LOW
Adobe Experience Manager < 6.5.22.0 and < 2024.11.0 - Security Feature Bypass via Improper Input Validation
CVSS 3.5
CVE-2024-52982 HIGH
Adobe Animate 23.0.0-23.0.8 and <=24.0.5 - Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2024-52051 HIGH
SIMATIC S7-PLCSIM V17-V19, STEP 7 V17-V19, WinCC Unified PC Runtime...
CVSS 7.3
CVE-2024-45761 MEDIUM
Dell OpenManage Server Administrator < 11.1.0.0 - Remote Code Execution via Web Plugin Injection
CVSS 5.4
CVE-2024-46901 LOW
Apache Subversion <1.14.4 - Info Disclosure
CVSS 3.1
CVE-2024-12355 LOW
Phone Contact Manager System 1.0 - Improper Input Validation in ContactBook::adding
CVSS 3.3
CVE-2024-12353 LOW
SourceCodester Phone Contact Manager System 1.0 - Improper Input Validation in User Menu
CVSS 3.3
CVE-2024-54140 LOW
sigstore-java < 1.2.0 - Insufficient Bundle Signature Verification in KeylessVerifier
CVE-2024-12138 MEDIUM
horilla < 1.2.1 - Remote Code Execution via Untrusted Data Deserialization
CVSS 6.3
CVE-2024-11985 MEDIUM
ASUS RT-AX55 RT-AX56U RT-AX57 RT-AX58U - Denial of Service via Improper Input Validation
CVSS 4.4
CVE-2024-52815 MEDIUM
Synapse < 1.120.1 - Denial of Service via Malformed Federation Invite
CVSS 5.3
CVE-2024-43052 HIGH
Qualcomm Mobile and FastConnect Platform Firmware - Memory Corruption in NPU
CVSS 7.8
CVE-2024-52337 MEDIUM
Fast Datapath for Red Hat Enterprise Linux - Log Spoofing via Improper Input Sanitization
CVSS 5.5
CVE-2024-22117 LOW
Zabbix 5.0.0-5.0.43 - Denial of Service via sysmapelementurlid Manipulation
CVSS 2.2
CVE-2024-11662 MEDIUM
welliamcao OpsManage <3.0.5 - Deserialization
CVSS 6.3
CVE-2024-11234 MEDIUM
PHP 8.1.0-8.1.30 - HTTP Request Smuggling via Proxy Stream URI Sanitization Bypass
CVSS 4.8
CVE-2024-9257 MEDIUM
Logsign Unified SecOps Platform < 6.4.26 - Authenticated Arbitrary File Deletion via delete_gsuite_key_file Endpoint
CVSS 6.5
Details
Vulnerabilities 12,451
Exploit Likelihood High