CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,451 vulnerabilities with CWE-20
CVE-2024-20464 HIGH
Cisco IOS XE - Unauthenticated Denial of Service via Crafted PIMv2 Packet
CVSS 8.6
CVE-2024-7023 HIGH
Google Chrome < 128.0.6537.0 - Privilege Escalation via Updater Data Validation
CVSS 8.8
CVE-2024-46946 CRITICAL
langchain-experimental 0.1.17-0.3.0 - Remote Code Execution via LLMSymbolicMathChain Sympy Sympify
CVSS 9.8
CVE-2024-37406 HIGH
Brave Android <1.67.116 - Info Disclosure
CVSS 7.5
CVE-2024-45601 HIGH
Mesop >=0.9.0 <0.12.4 - Unauthorized File Access via Insufficient Input Validation
CVSS 7.5
CVE-2024-8889 CRITICAL
CIRCUTOR TCP2RS+ 1.3b - Unauthenticated Configuration Modification via UDP Port 2000
CVSS 9.3
CVE-2024-45798 CRITICAL
arduino-esp32 - Poisoned Pipeline Execution via tests_results.yml Workflow
CVSS 9.9
CVE-2024-45612 MEDIUM
Contao 4.13.0-4.13.48 - Insert Tag Injection via Canonical URL
CVSS 5.3
CVE-2024-45537 MEDIUM
Apache Druid < 30.0.1 - Authenticated JDBC Property Injection via MySQL Connection String
CVSS 6.5
CVE-2024-34545 MEDIUM
Intel(R) RAID Web Console - Info Disclosure
CVSS 5.2
CVE-2024-21871 HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.5
CVE-2024-21829 HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.5
CVE-2024-21781 HIGH
Intel(R) Processors - Info Disclosure/DoS
CVSS 7.2
CVE-2024-44094 HIGH
Android - Memory Corruption via Improper Input Validation in ppmp_protect_mfcfw_buf
CVSS 7.8
CVE-2024-6077 HIGH
Rockwell Automation CompactLogix 5380 Firmware - Denial of Service via CIP Security Object
CVSS 7.5
CVE-2024-6658 HIGH
LoadMaster <7.2.60.0 - OS Command Injection
CVSS 8.4
CVE-2024-45825 HIGH
Rockwell Automation 5015-U8IHFT Firmware - Denial of Service via Malformed CIP Packet
CVSS 7.5
CVE-2024-20406 HIGH
Cisco IOS XR 6.8.1-6.9.9 - Unauthenticated Denial of Service via IS-IS Packet Input Validation
CVSS 7.4
CVE-2024-43455 HIGH
Windows Server 2008, 2012, 2016, 2019, 2022, 2022 23H2 - Spoofing via Remote Desktop Licensing Service
CVSS 8.8
CVE-2024-38245 HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38244 HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38243 HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38241 HIGH
Kernel Streaming Service Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38234 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-23H2 - Denial of Service in Networking Component
CVSS 6.5
CVE-2024-38230 MEDIUM
Windows Standards-Based Storage Management Service - DoS
CVSS 6.5
Details
Vulnerabilities 12,451
Exploit Likelihood High