The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,456 vulnerabilities with CWE-20
CVE-2024-38189
HIGH
KEV
Microsoft Project 2016 < 16.0.5461.1001 - Remote Code Execution
CVSS 8.8
CVE-2024-41976
HIGH
Siemens SCALANCE and RUGGEDCOM Firmware < 8.1 - Authenticated Remote Code Execution via VPN Configuration Input
CVSS 7.2
CVE-2024-41940
CRITICAL
SINEC NMS < 3.0 - Authenticated OS Command Injection via Privileged Command Queue
CVSS 9.1
CVE-2024-7512
MEDIUM
Concrete CMS 9.0.0-9.3.2 - Stored Cross-Site Scripting in Board Instances
CVSS 4.8
CVE-2024-30188
HIGH
Apache DolphinScheduler <3.2.2 - Info Disclosure
CVSS 8.1
CVE-2024-29831
HIGH
Apache DolphinScheduler < 3.2.2 - Authenticated Remote Code Execution via Switch Task Plugin
CVSS 8.8
CVE-2024-6254
MEDIUM
Brizy - Page Builder <= 2.5.1 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 4.3
CVE-2024-7005
MEDIUM
Google Chrome <127.0.6533.72 - Auth Bypass
CVSS 4.3
CVE-2024-7004
MEDIUM
Google Chrome < 127.0.6533.72 - Discretionary Access Control Bypass via Safe Browsing Input Validation
CVSS 4.3
CVE-2024-23483
HIGH
Zscaler Client Connector < 4.2 - OS Command Injection
CVSS 7.0
CVE-2024-6915
CRITICAL
JFrog Artifactory <7.90.6-7.59.23 - Cache Poisoning
CVSS 9.3
CVE-2024-21978
MEDIUM
AMD EPYC 7003 Series Firmware < milanpi_1.0.0.d - Unauthenticated Memory Read/Write via SEV-SNP Input Validation
CVSS 6.0
CVE-2024-40721
HIGH
TCBServiSign < 1.0.24.0318 - Unauthenticated DLL Loading via Improper Input Validation
CVSS 8.8
CVE-2024-40720
HIGH
TCBServiSign Windows < 1.0.24.0318 - Unauthenticated Arbitrary Command Execution via Registry Modification
CVSS 8.8
CVE-2024-38879
HIGH
Omnivise T3000 Application Server R9.2, R8.2 SP3, R8.2 SP4 - Unauthenticated Bypass via Exposed Internal Port
CVSS 7.5
CVE-2024-42458
CRITICAL
neatvnc < 0.8.1 - Improper Input Validation in Security Type Handling
CVSS 9.8
CVE-2024-4353
MEDIUM
Concrete CMS 9.0.0-9.3.2 - Stored Cross-Site Scripting in Dashboard Board Name Input
CVSS 4.8
CVE-2024-23600
LOW
PingIDM 7.0.0-7.4.9 - Information Disclosure via Query Filter Module
CVSS 2.7
CVE-2024-6978
MEDIUM
Cato Networks SDP Client < 5.10.28 - Unauthenticated Local Root Certificate Installation
CVSS 5.6
CVE-2024-6973
HIGH
Cato Windows SDP Client < 5.10.34 - Remote Code Execution via Crafted URLs
CVSS 7.5
CVE-2024-7340
HIGH
Weave < 0.50.8 - Path Traversal and Arbitrary File Read via Server API
CVSS 8.8
CVE-2024-39950
HIGH
Dahua NVR4104-4KS2/L < 4.003.0000000.1.r.240515 - Stack-based Buffer Overflow
CVSS 8.6
CVE-2024-39949
HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Reachable Assertion
CVSS 7.5
CVE-2024-39948
HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
CVE-2024-39944
HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
Details
Vulnerabilities
12,456
Exploit Likelihood
High