CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,462 vulnerabilities with CWE-20
CVE-2024-6973 HIGH
Cato Windows SDP Client < 5.10.34 - Remote Code Execution via Crafted URLs
CVSS 7.5
CVE-2024-7340 HIGH
Weave < 0.50.8 - Path Traversal and Arbitrary File Read via Server API
CVSS 8.8
CVE-2024-39950 HIGH
Dahua NVR4104-4KS2/L < 4.003.0000000.1.r.240515 - Stack-based Buffer Overflow
CVSS 8.6
CVE-2024-39949 HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Reachable Assertion
CVSS 7.5
CVE-2024-39948 HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
CVE-2024-39944 HIGH
Dahuasecurity Nvr4104-4ks2/l Firmware - Improper Input Validation
CVSS 7.5
CVE-2024-41945 LOW
fuels-ts < 0.93.0 - Transaction Failure via UTXO Reuse in Account Fund Function
CVSS 3.1
CVE-2024-5969 MEDIUM
AIomatic < 2.0.5 - Unauthenticated Arbitrary Email Sending via aiomatic_send_email Function
CVSS 5.8
CVE-2024-41120 CRITICAL
streamlit-geospatial < 2024-07-19 - Server-Side Request Forgery via URL Parameter in Vector Data Visualization
CVSS 9.8
CVE-2024-41119 CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Unsafe eval() on vis_params Input
CVSS 9.8
CVE-2024-41117 CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via vis_params eval Injection
CVSS 9.8
CVE-2024-41116 CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via vis_params Eval Injection
CVSS 9.8
CVE-2024-41115 CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Unsanitized Palette Input in eval()
CVSS 9.8
CVE-2024-41114 CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Unsanitized Palette Input
CVSS 9.8
CVE-2024-41113 CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via vis_params eval Injection
CVSS 9.8
CVE-2024-41112 CRITICAL
streamlit-geospatial < 2024-07-19 - Remote Code Execution via Palette Variable Eval Injection
CVSS 9.8
CVE-2024-35296 HIGH
Apache Traffic Server 8.0.0-8.1.10 and 9.0.0-9.2.4 - Denial of Service via Invalid Accept-Encoding Header
CVSS 8.2
CVE-2024-25090 MEDIUM
Apache Roller 5.0.0-6.1.2 - Authenticated Stored Cross-Site Scripting in Profile and Bookmark Features
CVSS 5.4
CVE-2024-3938 MEDIUM
dotcms 5.1.5-23.01.18 - HTML Injection via Reset Password URL Parameter
CVSS 5.4
CVE-2024-29068 MEDIUM
snapd < 2.62 - Denial of Service via Non-Regular File Extraction
CVSS 5.8
CVE-2024-41839 LOW
Adobe Experience Manager < 6.5.21.0 and < 2024.5.0 - Security Feature Bypass via Improper Input Validation
CVSS 3.5
CVE-2024-7014 HIGH
Telegram < 10.14.5 - Malicious App Disguised as Video via EvilVideo Vulnerability
CVSS 8.1
CVE-2024-32007 HIGH
Apache CXF <4.0.5, 3.6.4, 3.5.9 - DoS
CVSS 7.5
CVE-2024-40642 HIGH
netty-incubator-codec-ohttp < 0.0.13 - HTTP Request Smuggling and Injection via BinaryHttpParser
CVSS 8.1
CVE-2024-23469 CRITICAL
SolarWinds Access Rights Manager < 2023.2.4 - Unauthenticated Remote Code Execution
CVSS 9.6
Details
Vulnerabilities 12,462
Exploit Likelihood High