The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,451 vulnerabilities with CWE-20
CVE-2024-20464
HIGH
Cisco IOS XE - Unauthenticated Denial of Service via Crafted PIMv2 Packet
CVSS 8.6
CVE-2024-7023
HIGH
Google Chrome < 128.0.6537.0 - Privilege Escalation via Updater Data Validation
CVSS 8.8
CVE-2024-46946
CRITICAL
langchain-experimental 0.1.17-0.3.0 - Remote Code Execution via LLMSymbolicMathChain Sympy Sympify
CVSS 9.8
CVE-2024-37406
HIGH
Brave Android <1.67.116 - Info Disclosure
CVSS 7.5
CVE-2024-45601
HIGH
Mesop >=0.9.0 <0.12.4 - Unauthorized File Access via Insufficient Input Validation
CVSS 7.5
CVE-2024-8889
CRITICAL
CIRCUTOR TCP2RS+ 1.3b - Unauthenticated Configuration Modification via UDP Port 2000
CVSS 9.3
CVE-2024-45798
CRITICAL
arduino-esp32 - Poisoned Pipeline Execution via tests_results.yml Workflow
CVSS 9.9
CVE-2024-45612
MEDIUM
Contao 4.13.0-4.13.48 - Insert Tag Injection via Canonical URL
CVSS 5.3
CVE-2024-45537
MEDIUM
Apache Druid < 30.0.1 - Authenticated JDBC Property Injection via MySQL Connection String
CVSS 6.5
CVE-2024-34545
MEDIUM
Intel(R) RAID Web Console - Info Disclosure
CVSS 5.2
CVE-2024-21871
HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.5
CVE-2024-21829
HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.5
CVE-2024-21781
HIGH
Intel(R) Processors - Info Disclosure/DoS
CVSS 7.2
CVE-2024-44094
HIGH
Android - Memory Corruption via Improper Input Validation in ppmp_protect_mfcfw_buf
CVSS 7.8
CVE-2024-6077
HIGH
Rockwell Automation CompactLogix 5380 Firmware - Denial of Service via CIP Security Object
CVSS 7.5
CVE-2024-6658
HIGH
LoadMaster <7.2.60.0 - OS Command Injection
CVSS 8.4
CVE-2024-45825
HIGH
Rockwell Automation 5015-U8IHFT Firmware - Denial of Service via Malformed CIP Packet
CVSS 7.5
CVE-2024-20406
HIGH
Cisco IOS XR 6.8.1-6.9.9 - Unauthenticated Denial of Service via IS-IS Packet Input Validation
CVSS 7.4
CVE-2024-43455
HIGH
Windows Server 2008, 2012, 2016, 2019, 2022, 2022 23H2 - Spoofing via Remote Desktop Licensing Service
CVSS 8.8
CVE-2024-38245
HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38244
HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38243
HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38241
HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38234
MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-23H2 - Denial of Service in Networking Component
CVSS 6.5
CVE-2024-38230
MEDIUM
Windows Standards-Based Storage Management Service - DoS
CVSS 6.5
Details
Vulnerabilities
12,451
Exploit Likelihood
High