CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2024-23668 HIGH
FortiWebManager 6.2.3-6.2.4, 6.3.0, 7.0.0-7.0.4, 7.2.0 - Unauthenticated Remote Code Execution via HTTP Requests or CLI
CVSS 8.8
CVE-2024-36390 HIGH
MileSight DeviceHub - Denial of Service via Improper Input Validation
CVSS 7.5
CVE-2024-5138 HIGH
snapd 2.51.6-2.63.1 - Privilege Escalation via snapctl Command-Line Argument Parsing
CVSS 8.1
CVE-2024-34009 HIGH
Moodle 4.3.0-4.3.3 - Unauthenticated ReCAPTCHA Bypass on Login Page
CVSS 7.5
CVE-2024-33999 CRITICAL
Moodle 4.3.0-4.3.4 - Improper Input Validation in MFA Referrer URL
CVSS 9.8
CVE-2024-33996 MEDIUM
Calendar Web Service - Info Disclosure
CVSS 6.2
CVE-2024-22338 MEDIUM
IBM Security Verify Access OIDC Provider <23.03 - Info Disclosure
CVSS 4.0
CVE-2024-3584 HIGH
qdrant/qdrant <1.9.0-dev - Path Traversal
CVSS 7.5
CVE-2024-3657 HIGH
Red Hat Directory Server - Denial of Service via Specially-Crafted LDAP Query
CVSS 7.5
CVE-2024-2199 MEDIUM
Red Hat Directory Server - Authenticated Denial of Service via Malformed userPassword Input
CVSS 5.7
CVE-2024-35384 MEDIUM
Cesanta mjs 2.20.0 - Denial of Service via mjs_array_length Function
CVSS 5.5
CVE-2024-4287 HIGH
mintplex-labs/anything-llm - Privilege Escalation
CVSS 7.2
CVE-2024-36053 CRITICAL
mintupload <4.2.0 - Command Injection
CVSS 9.0
CVE-2024-22429 HIGH
Dell BIOS - Authenticated Arbitrary Code Execution via Improper Input Validation
CVSS 7.5
CVE-2024-22120 CRITICAL
Zabbix 6.0.0-6.0.27 - Time-Based Blind SQL Injection via Audit Log Client IP Field
CVSS 9.1
CVE-2024-24981 HIGH
Intel(R) Server M50FCP - Privilege Escalation
CVSS 7.5
CVE-2024-23487 HIGH
Intel(R) Server D50DNP - Privilege Escalation
CVSS 7.5
CVE-2024-22476 CRITICAL
Intel Neural Compressor <2.5.0 - SQL Injection
CVSS 10.0
CVE-2024-22390 MEDIUM
Intel FPGA products < 2.9.1 - Denial of Service via Improper Input Validation
CVSS 4.4
CVE-2024-22382 HIGH
Intel(R) Server D50DNP - Privilege Escalation
CVSS 7.5
CVE-2024-22095 HIGH
Intel(R) Server D50DNP - Privilege Escalation
CVSS 7.2
CVE-2024-22015 MEDIUM
Intel(R) DLB driver software < 8.5.0 - Authenticated Denial of Service via Improper Input Validation
CVSS 6.5
CVE-2024-4609 CRITICAL
Rockwell Automation FactoryTalk View < 11.0 - SQL Injection via Datalog Function
CVSS 9.8
CVE-2024-4321 HIGH
gaizhenbiao/chuanhuchatgpt 20240310 - Local File Inclusion via Chat History Upload Name Parameter
CVSS 7.5
CVE-2024-25743 HIGH
Linux kernel through 6.9 - Untrusted Hypervisor Virtual Interrupt Injection
CVSS 7.1
Details
Vulnerabilities 12,465
Exploit Likelihood High