The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,462 vulnerabilities with CWE-20
CVE-2024-6973
HIGH
Cato Windows SDP Client < 5.10.34 - Remote Code Execution via Crafted URLs
CVSS 7.5
CVE-2024-7340
HIGH
Weave < 0.50.8 - Path Traversal and Arbitrary File Read via Server API
CVSS 8.8
CVE-2024-39950
HIGH
Dahua NVR4104-4KS2/L < 4.003.0000000.1.r.240515 - Stack-based Buffer Overflow
CVSS 8.6
CVE-2024-39949
HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Reachable Assertion
CVSS 7.5
CVE-2024-39948
HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
CVE-2024-39944
HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
CVE-2024-41945
LOW
fuels-ts < 0.93.0 - Transaction Failure via UTXO Reuse in Account Fund Function
CVSS 3.1
CVE-2024-5969
MEDIUM
AIomatic < 2.0.5 - Unauthenticated Arbitrary Email Sending via aiomatic_send_email Function
CVSS 5.8
CVE-2024-41120
CRITICAL
streamlit-geospatial < 2024-07-19 - Server-Side Request Forgery via URL Parameter in Vector Data Visualization
CVSS 9.8
CVE-2024-41119
CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Unsafe eval() on vis_params Input
CVSS 9.8
CVE-2024-41117
CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via vis_params eval Injection
CVSS 9.8
CVE-2024-41116
CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via vis_params Eval Injection
CVSS 9.8
CVE-2024-41115
CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Unsanitized Palette Input in eval()
CVSS 9.8
CVE-2024-41114
CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Unsanitized Palette Input
CVSS 9.8
CVE-2024-41113
CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via vis_params eval Injection
CVSS 9.8
CVE-2024-41112
CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Palette Variable Eval Injection
CVSS 9.8
CVE-2024-35296
HIGH
Apache Traffic Server 8.0.0-8.1.10 and 9.0.0-9.2.4 - Denial of Service via Invalid Accept-Encoding Header
CVSS 8.2
CVE-2024-25090
MEDIUM
Apache Roller 5.0.0-6.1.2 - Authenticated Stored Cross-Site Scripting in Profile and Bookmark Features
CVSS 5.4
CVE-2024-3938
MEDIUM
dotcms 5.1.5-23.01.18 - HTML Injection via Reset Password URL Parameter
CVSS 5.4
CVE-2024-29068
MEDIUM
snapd < 2.62 - Denial of Service via Non-Regular File Extraction
CVSS 5.8
CVE-2024-41839
LOW
Adobe Experience Manager < 6.5.21.0 and < 2024.5.0 - Security Feature Bypass via Improper Input Validation
CVSS 3.5
CVE-2024-7014
HIGH
Telegram < 10.14.5 - Malicious App Disguised as Video via EvilVideo Vulnerability
CVSS 8.1
CVE-2024-32007
HIGH
Apache CXF <4.0.5, 3.6.4, 3.5.9 - DoS
CVSS 7.5
CVE-2024-40642
HIGH
netty-incubator-codec-ohttp < 0.0.13 - HTTP Request Smuggling and Injection via BinaryHttpParser
CVSS 8.1
CVE-2024-23469
CRITICAL
SolarWinds Access Rights Manager < 2023.2.4 - Unauthenticated Remote Code Execution
CVSS 9.6
Details
Vulnerabilities
12,462
Exploit Likelihood
High