CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2024-38021 HIGH
Microsoft Outlook - Remote Code Execution
CVSS 8.8
CVE-2024-22271 HIGH
Spring Cloud Function <4.1.2, <4.0.8 - DoS
CVSS 8.2
CVE-2024-35227 HIGH
Discourse < 3.2.3 - Denial of Service via Malicious Onebox URL
CVSS 7.5
CVE-2024-32755 CRITICAL
American Dynamics Illustra Essentials Gen 4 < Illustra.Ess4.01.02.10.5982 - Improper Input Validation
CVSS 9.1
CVE-2024-0158 MEDIUM
Dell Alienware and Chengming Firmware - Denial of Service and Privilege Escalation via UEFI Variable Modification
CVSS 5.1
CVE-2024-39573 HIGH
Apache HTTP Server < 2.4.60 - Server-Side Request Forgery via mod_rewrite RewriteRule
CVSS 7.5
CVE-2024-6376 HIGH
MongoDB Compass <1.42.2 - Code Injection
CVSS 7.0
CVE-2024-38525 HIGH
dd-trace-cpp <0.2.2 - Memory Corruption
CVSS 7.5
CVE-2024-30110 LOW
HCL DRYiCE AEX - Cross-Site Scripting via Input Validation Bypass
CVSS 3.7
CVE-2024-5276 CRITICAL
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
CVSS 9.8
CVE-2024-5990 HIGH
Rockwell Automation ThinManager/ThinServer 11.1.0-11.1.7 DoS via Malicious Monitor Thread Message
CVSS 7.5
CVE-2024-5989 CRITICAL
Rockwell Automation ThinManager and ThinServer 11.1.0-11.1.7 - Unauthenticated SQL Injection and Remote Code Execution
CVSS 9.8
CVE-2024-5988 CRITICAL
Rockwell Automation ThinManager/ThinServer 11.1.0-11.1.7 - Remote Code Execution
CVSS 9.8
CVE-2024-21519 MEDIUM
OpenCart >= 4.0.0.0 - Authenticated Arbitrary File Creation via Database Restoration
CVSS 6.6
CVE-2024-6239 HIGH
Poppler - Denial of Service via Pdfinfo -dests Parameter
CVSS 7.5
CVE-2024-38359 MEDIUM
Lightning Network Daemon <0.17.0 - DoS
CVSS 6.5
CVE-2024-37346 MEDIUM
Absolute Secure Access < 13.06 - Authenticated Denial of Service via Warehouse Invalid Data
CVSS 4.9
CVE-2024-34693 MEDIUM
Apache Superset < 3.1.3 - Authenticated File Read via MariaDB Connection with local_infile
CVSS 6.8
CVE-2024-38355 HIGH
Socket.IO < 2.5.1 and 3.0.0-4.6.2 - Denial of Service via Crafted Packet
CVSS 7.3
CVE-2024-4787 MEDIUM
Cost Calculator Builder PRO <3.1.75 - XSS
CVSS 5.8
CVE-2024-5533 MEDIUM
Divi <= 4.25.1 - Authenticated Stored Cross-Site Scripting
CVSS 6.4
CVE-2024-37794 HIGH
CVC5 Solver 1.1.3 - Denial of Service via Crafted SMT2 Input File
CVSS 7.5
CVE-2024-32907 HIGH
Android - Local Privilege Escalation via memcall_add Buffer Overflow
CVSS 7.8
CVE-2024-32903 HIGH
Android - Local Privilege Escalation via Improper Input Validation in lwis_transaction.c
CVSS 7.8
CVE-2024-32860 HIGH
Dell Alienware BIOS < 1.26.0 - Authenticated Code Execution via Improper Input Validation
CVSS 7.5
Details
Vulnerabilities 12,465
Exploit Likelihood High