CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,456 vulnerabilities with CWE-20
CVE-2024-38189 HIGH KEV
Microsoft Project 2016 < 16.0.5461.1001 - Remote Code Execution
CVSS 8.8
CVE-2024-41976 HIGH
Siemens SCALANCE and RUGGEDCOM Firmware < 8.1 - Authenticated Remote Code Execution via VPN Configuration Input
CVSS 7.2
CVE-2024-41940 CRITICAL
SINEC NMS < 3.0 - Authenticated OS Command Injection via Privileged Command Queue
CVSS 9.1
CVE-2024-7512 MEDIUM
Concrete CMS 9.0.0-9.3.2 - Stored Cross-Site Scripting in Board Instances
CVSS 4.8
CVE-2024-30188 HIGH
Apache DolphinScheduler <3.2.2 - Info Disclosure
CVSS 8.1
CVE-2024-29831 HIGH
Apache DolphinScheduler < 3.2.2 - Authenticated Remote Code Execution via Switch Task Plugin
CVSS 8.8
CVE-2024-6254 MEDIUM
Brizy - Page Builder <= 2.5.1 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 4.3
CVE-2024-7005 MEDIUM
Google Chrome <127.0.6533.72 - Auth Bypass
CVSS 4.3
CVE-2024-7004 MEDIUM
Google Chrome < 127.0.6533.72 - Discretionary Access Control Bypass via Safe Browsing Input Validation
CVSS 4.3
CVE-2024-23483 HIGH
Zscaler Client Connector < 4.2 - OS Command Injection
CVSS 7.0
CVE-2024-6915 CRITICAL
JFrog Artifactory <7.90.6-7.59.23 - Cache Poisoning
CVSS 9.3
CVE-2024-21978 MEDIUM
AMD EPYC 7003 Series Firmware < milanpi_1.0.0.d - Unauthenticated Memory Read/Write via SEV-SNP Input Validation
CVSS 6.0
CVE-2024-40721 HIGH
TCBServiSign < 1.0.24.0318 - Unauthenticated DLL Loading via Improper Input Validation
CVSS 8.8
CVE-2024-40720 HIGH
TCBServiSign Windows < 1.0.24.0318 - Unauthenticated Arbitrary Command Execution via Registry Modification
CVSS 8.8
CVE-2024-38879 HIGH
Omnivise T3000 Application Server R9.2, R8.2 SP3, R8.2 SP4 - Unauthenticated Bypass via Exposed Internal Port
CVSS 7.5
CVE-2024-42458 CRITICAL
neatvnc < 0.8.1 - Improper Input Validation in Security Type Handling
CVSS 9.8
CVE-2024-4353 MEDIUM
Concrete CMS 9.0.0-9.3.2 - Stored Cross-Site Scripting in Dashboard Board Name Input
CVSS 4.8
CVE-2024-23600 LOW
PingIDM 7.0.0-7.4.9 - Information Disclosure via Query Filter Module
CVSS 2.7
CVE-2024-6978 MEDIUM
Cato Networks SDP Client < 5.10.28 - Unauthenticated Local Root Certificate Installation
CVSS 5.6
CVE-2024-6973 HIGH
Cato Windows SDP Client < 5.10.34 - Remote Code Execution via Crafted URLs
CVSS 7.5
CVE-2024-7340 HIGH
Weave < 0.50.8 - Path Traversal and Arbitrary File Read via Server API
CVSS 8.8
CVE-2024-39950 HIGH
Dahua NVR4104-4KS2/L < 4.003.0000000.1.r.240515 - Stack-based Buffer Overflow
CVSS 8.6
CVE-2024-39949 HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Reachable Assertion
CVSS 7.5
CVE-2024-39948 HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
CVE-2024-39944 HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
Details
Vulnerabilities 12,456
Exploit Likelihood High