CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2024-2536 MEDIUM
Rank Math SEO - AI SEO Tools < 1.0.214 - Authenticated Stored Cross-Site Scripting via HowTo Block Attributes
CVSS 6.4
CVE-2024-2513 MEDIUM
WP Chat App <= 3.6.2 - Authenticated Stored Cross-Site Scripting via ImageAlt Block Attribute
CVSS 6.4
CVE-2024-2226 MEDIUM
Otter Blocks < 2.6.5 - Authenticated Stored Cross-Site Scripting via Google Map Block ID Parameter
CVSS 6.4
CVE-2024-2165 MEDIUM
SEOPress - On-site SEO < 7.5.2.1 - Authenticated Stored Cross-Site Scripting via Image Alt Parameter
CVSS 6.4
CVE-2024-2027 MEDIUM
Real Media Library < 4.22.7 - Authenticated Stored Cross-Site Scripting via Style Attributes
CVSS 6.4
CVE-2024-25116 MEDIUM
RedisBloom 2.0.0-2.4.6 and 2.5.0-2.6.9 - Authenticated Denial of Service via CF.RESERVE Command
CVSS 5.5
CVE-2024-31867 MEDIUM
Apache Zeppelin <0.11.1 - SQL Injection
CVSS 6.5
CVE-2024-28897 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-23H2 - Secure Boot Security Feature Bypass
CVSS 6.8
CVE-2024-26253 MEDIUM
Windows rndismp6.sys - Remote Code Execution
CVSS 6.8
CVE-2024-26240 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2008-2012 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-26189 HIGH
Windows Secure Boot - Security Feature Bypass via Improper Input Validation
CVSS 8.0
CVE-2024-20670 HIGH
Outlook for Windows < 1.2023.0322.0100 - Spoofing via Improper Input Validation
CVSS 8.1
CVE-2024-31865 MEDIUM
Apache Zeppelin <0.11.1 - Privilege Escalation
CVSS 6.5
CVE-2024-31862 MEDIUM
Apache Zeppelin <0.11.0 - Info Disclosure
CVSS 5.3
CVE-2024-27896 HIGH
Huawei EMUI and HarmonyOS - Improper Input Validation in Log Module
CVSS 7.5
CVE-2024-27912 HIGH
Lenovo Printers - Denial of Service via Crafted LPD Packets
CVSS 7.5
CVE-2024-27909 MEDIUM
Lenovo Printers - Denial of Service via HTTPS Service
CVSS 4.9
CVE-2024-0080 LOW
NVIDIA nvTIFF Library < 0.3.0 - Partial Denial of Service via Crafted Input File
CVSS 2.8
CVE-2024-31212 MEDIUM
InstantCMS 2.16.2 - Authenticated SQL Injection via index_chart_data period Parameter
CVSS 6.7
CVE-2024-29008 MEDIUM
Apache CloudStack 4.14.0.0-4.18.1.0 - Unauthenticated Host Device Attachment via Extraconfig Feature
CVSS 6.4
CVE-2024-2689 MEDIUM
Temporal Server <1.20.5, 1.21.6, 1.22.7 - DoS
CVSS 4.4
CVE-2024-20334 MEDIUM
Cisco TelePresence Management Suite - XSS
CVSS 5.5
CVE-2024-27201 MEDIUM
Open Automation Software OAS Platform <19.00.0057 - Info Disclosure
CVSS 4.9
CVE-2024-27254 MEDIUM
IBM Db2 10.5, 11.1, 11.5 - Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2024-25046 MEDIUM
IBM Db2 11.1 and 11.5 - Authenticated Denial of Service via Specially Crafted Query
CVSS 5.3
Details
Vulnerabilities 12,465
Exploit Likelihood High