CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,451 vulnerabilities with CWE-20
CVE-2024-23386 MEDIUM
Qualcomm Wsa8835 Firmware - Improper Input Validation
CVSS 6.7
CVE-2024-33700 HIGH
LevelOne WBR-6012 Firmware R0.40e6 - Denial of Service via Malformed FTP Commands
CVSS 7.5
CVE-2024-22065 MEDIUM
ZTE MF258 Pro Firmware - Authenticated OS Command Injection via Ping Diagnosis Interface
CVSS 6.8
CVE-2024-45802 HIGH
squid 3.0-6.9 - Denial of Service via Trusted Server Response
CVSS 7.5
CVE-2024-0127 HIGH
NVIDIA vGPU and Cloud Gaming < 17.4, 16.8, and October 2024 - Improper Input Validation in GPU Kernel Driver
CVSS 7.8
CVE-2024-0126 HIGH
NVIDIA GPU Display Driver - Privilege Escalation
CVSS 8.2
CVE-2024-49753 MEDIUM
Zitadel < 2.58.7, 2.64.0 - Server-Side Request Forgery via DNS Record Bypass
CVSS 5.9
CVE-2024-20495 HIGH
Cisco Adaptive Security Appliance Software - Unauthenticated Denial of Service via Remote Access VPN Key Validation
CVSS 8.6
CVE-2024-20274 MEDIUM
Cisco Secure Firewall Management Center - XSS
CVSS 5.5
CVE-2024-48919 CRITICAL
Cursor <Sep 27, 2024 - Code Injection
CVE-2024-49368 CRITICAL
nginxui/nginx_ui < 2.0.0-beta.36 - OS Command Injection via Logrotate Configuration
CVSS 9.8
CVE-2024-49361 HIGH
ACON <= 1.1.0 Input Validation - Remote Code Execution
CVE-2024-48918 HIGH
RDSlight < 1.1.0 - Command Injection and Memory Tampering via User Input Handling
CVE-2024-9348 HIGH
Docker Desktop < 4.34.3 - Remote Code Execution via GitHub Source Link in Build View
CVE-2024-45219 HIGH
Apache CloudStack <4.18.2.3-4.19.1.1 - Info Disclosure
CVSS 8.5
CVE-2024-48914 CRITICAL
Vendure asset-server-plugin < 2.3.3 and 3.0.0-3.0.5 - Path Traversal and Denial of Service via Malformed URI
CVSS 9.1
CVE-2024-6207 HIGH
Rockwell Automation PN1550 - Privilege Escalation
CVSS 7.5
CVE-2024-8755 HIGH
LoadMaster <7.2.60.1 - OS Command Injection
CVSS 8.4
CVE-2024-9507 MEDIUM
The Contact Form by Bit Form <2.15.2 - Info Disclosure
CVSS 4.9
CVE-2024-45117 HIGH
Adobe Commerce <2.4.7-p2 - Info Disclosure
CVSS 7.6
CVE-2024-47823 CRITICAL
Livewire <2.12.7-3.5.2 - Code Injection
CVSS 9.8
CVE-2024-43611 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43593 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43592 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43561 MEDIUM
Windows Mobile Broadband Driver - Denial of Service via Out-of-bounds Read
CVSS 6.5
Details
Vulnerabilities 12,451
Exploit Likelihood High