CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2024-20394 MEDIUM
Cisco AppDynamics Network Visibility Agent - DoS
CVSS 5.5
CVE-2024-3968 HIGH
OpenText iManager <3.2.6.0200 - RCE
CVSS 7.8
CVE-2024-3488 MEDIUM
OpenText iManager 3.0-3.2.6 - Unauthenticated Unrestricted File Upload
CVSS 5.6
CVE-2024-2248 MEDIUM
JFrog <7.85.0/7.84.7 - Header Injection
CVSS 6.4
CVE-2024-34098 HIGH
Acrobat Reader <20.005.30574, 24.002.20736 - RCE
CVSS 7.8
CVE-2024-3676 HIGH
Proofpoint Enterprise Protection - SQL Injection
CVSS 7.5
CVE-2024-30054 MEDIUM
Microsoft Power BI Client JavaScript SDK - Info Disclosure
CVSS 6.5
CVE-2024-30040 HIGH KEV
Windows MSHTML < - Privilege Escalation
CVSS 8.8
CVE-2024-30002 MEDIUM
Microsoft Windows Mobile Broadband Driver - Remote Code Execution
CVSS 6.8
CVE-2024-29998 MEDIUM
Microsoft Windows Mobile Broadband Driver - Remote Code Execution
CVSS 6.8
CVE-2024-3372 HIGH
MongoDB <7.0.6-6.0.14-5.0.25 - SSRF
CVSS 7.5
CVE-2024-25970 MEDIUM
Dell PowerScale OneFS 8.2.x-9.7.0.1 - Loss of Integrity via Improper Input Validation
CVSS 6.5
CVE-2024-34365 CRITICAL
Apache Karaf Cave - Improper Input Validation
CVSS 9.1
CVE-2024-32992 HIGH
Huawei EMUI and HarmonyOS - Denial of Service in Baseband Module
CVSS 7.5
CVE-2024-32990 MEDIUM
Huawei EMUI and HarmonyOS - Denial of Service via System Sharing Pop-Up Module
CVSS 6.1
CVE-2024-32989 LOW
Huawei EMUI and HarmonyOS - Denial of Service via System Sharing Pop-up Module
CVSS 3.3
CVE-2024-32672 MEDIUM
Samsung Open Source Escargot <4.0.0 - DoS
CVSS 5.3
CVE-2024-32669 MEDIUM
Samsung Open Source escargot <4.0.0 - Buffer Overflow
CVSS 5.3
CVE-2024-30258 HIGH
eprosima Fast-DDS < 2.6.8 - Denial of Service via Malformed RTPS Packet
CVSS 8.2
CVE-2024-2257 CRITICAL
Digisol Router <3.2.02 - Info Disclosure
CVSS 9.1
CVE-2024-25641 CRITICAL
Cacti Import Packages RCE
CVSS 9.1
CVE-2024-25581 HIGH
DNSdist - Denial of Service via DNS over HTTPS AXFR/IXFR Request
CVSS 7.5
CVE-2024-2746 HIGH
dnf5daemon-server - Unauthenticated Denial of Service and Information Disclosure via INI File Parsing
CVSS 8.8
CVE-2024-1929 HIGH
dnf5daemon-server <5.1.17 - Privilege Escalation
CVSS 7.5
CVE-2024-23707 HIGH
Android - Local Privilege Escalation via Improper Input Validation
CVSS 7.8
Details
Vulnerabilities 12,465
Exploit Likelihood High