The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,465 vulnerabilities with CWE-20
CVE-2024-23668
HIGH
FortiWebManager 6.2.3-6.2.4, 6.3.0, 7.0.0-7.0.4, 7.2.0 - Unauthenticated Remote Code Execution via HTTP Requests or CLI
CVSS 8.8
CVE-2024-36390
HIGH
MileSight DeviceHub - Denial of Service via Improper Input Validation
CVSS 7.5
CVE-2024-5138
HIGH
snapd 2.51.6-2.63.1 - Privilege Escalation via snapctl Command-Line Argument Parsing
CVSS 8.1
CVE-2024-34009
HIGH
Moodle 4.3.0-4.3.3 - Unauthenticated ReCAPTCHA Bypass on Login Page
CVSS 7.5
CVE-2024-33999
CRITICAL
Moodle 4.3.0-4.3.4 - Improper Input Validation in MFA Referrer URL
CVSS 9.8
CVE-2024-33996
MEDIUM
Calendar Web Service - Info Disclosure
CVSS 6.2
CVE-2024-22338
MEDIUM
IBM Security Verify Access OIDC Provider <23.03 - Info Disclosure
CVSS 4.0
CVE-2024-3584
HIGH
qdrant/qdrant <1.9.0-dev - Path Traversal
CVSS 7.5
CVE-2024-3657
HIGH
Red Hat Directory Server - Denial of Service via Specially-Crafted LDAP Query
CVSS 7.5
CVE-2024-2199
MEDIUM
Red Hat Directory Server - Authenticated Denial of Service via Malformed userPassword Input
CVSS 5.7
CVE-2024-35384
MEDIUM
Cesanta mjs 2.20.0 - Denial of Service via mjs_array_length Function
CVSS 5.5
CVE-2024-4287
HIGH
mintplex-labs/anything-llm - Privilege Escalation
CVSS 7.2
CVE-2024-36053
CRITICAL
mintupload <4.2.0 - Command Injection
CVSS 9.0
CVE-2024-22429
HIGH
Dell BIOS - Authenticated Arbitrary Code Execution via Improper Input Validation
CVSS 7.5
CVE-2024-22120
CRITICAL
Zabbix 6.0.0-6.0.27 - Time-Based Blind SQL Injection via Audit Log Client IP Field
CVSS 9.1
CVE-2024-24981
HIGH
Intel(R) Server M50FCP - Privilege Escalation
CVSS 7.5
CVE-2024-23487
HIGH
Intel(R) Server D50DNP - Privilege Escalation
CVSS 7.5
CVE-2024-22476
CRITICAL
Intel Neural Compressor <2.5.0 - SQL Injection
CVSS 10.0
CVE-2024-22390
MEDIUM
Intel FPGA products < 2.9.1 - Denial of Service via Improper Input Validation
CVSS 4.4
CVE-2024-22382
HIGH
Intel(R) Server D50DNP - Privilege Escalation
CVSS 7.5
CVE-2024-22095
HIGH
Intel(R) Server D50DNP - Privilege Escalation
CVSS 7.2
CVE-2024-22015
MEDIUM
Intel(R) DLB driver software < 8.5.0 - Authenticated Denial of Service via Improper Input Validation
CVSS 6.5
CVE-2024-4609
CRITICAL
Rockwell Automation FactoryTalk View < 11.0 - SQL Injection via Datalog Function
CVSS 9.8
CVE-2024-4321
HIGH
gaizhenbiao/chuanhuchatgpt 20240310 - Local File Inclusion via Chat History Upload Name Parameter
CVSS 7.5
CVE-2024-25743
HIGH
Linux kernel through 6.9 - Untrusted Hypervisor Virtual Interrupt Injection
CVSS 7.1
Details
Vulnerabilities
12,465
Exploit Likelihood
High