The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,465 vulnerabilities with CWE-20
CVE-2024-2536
MEDIUM
Rank Math SEO - AI SEO Tools < 1.0.214 - Authenticated Stored Cross-Site Scripting via HowTo Block Attributes
CVSS 6.4
CVE-2024-2513
MEDIUM
WP Chat App <= 3.6.2 - Authenticated Stored Cross-Site Scripting via ImageAlt Block Attribute
CVSS 6.4
CVE-2024-2226
MEDIUM
Otter Blocks < 2.6.5 - Authenticated Stored Cross-Site Scripting via Google Map Block ID Parameter
CVSS 6.4
CVE-2024-2165
MEDIUM
SEOPress - On-site SEO < 7.5.2.1 - Authenticated Stored Cross-Site Scripting via Image Alt Parameter
CVSS 6.4
CVE-2024-2027
MEDIUM
Real Media Library < 4.22.7 - Authenticated Stored Cross-Site Scripting via Style Attributes
CVSS 6.4
CVE-2024-25116
MEDIUM
RedisBloom 2.0.0-2.4.6 and 2.5.0-2.6.9 - Authenticated Denial of Service via CF.RESERVE Command
CVSS 5.5
CVE-2024-31867
MEDIUM
Apache Zeppelin <0.11.1 - SQL Injection
CVSS 6.5
CVE-2024-28897
MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-23H2 - Secure Boot Security Feature Bypass
CVSS 6.8
CVE-2024-26253
MEDIUM
Windows rndismp6.sys - Remote Code Execution
CVSS 6.8
CVE-2024-26240
HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2008-2012 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-26189
HIGH
Windows Secure Boot - Security Feature Bypass via Improper Input Validation
CVSS 8.0
CVE-2024-20670
HIGH
Outlook for Windows < 1.2023.0322.0100 - Spoofing via Improper Input Validation
CVSS 8.1
CVE-2024-31865
MEDIUM
Apache Zeppelin <0.11.1 - Privilege Escalation
CVSS 6.5
CVE-2024-31862
MEDIUM
Apache Zeppelin <0.11.0 - Info Disclosure
CVSS 5.3
CVE-2024-27896
HIGH
Huawei EMUI and HarmonyOS - Improper Input Validation in Log Module
CVSS 7.5
CVE-2024-27912
HIGH
Lenovo Printers - Denial of Service via Crafted LPD Packets
CVSS 7.5
CVE-2024-27909
MEDIUM
Lenovo Printers - Denial of Service via HTTPS Service
CVSS 4.9
CVE-2024-0080
LOW
NVIDIA nvTIFF Library < 0.3.0 - Partial Denial of Service via Crafted Input File
CVSS 2.8
CVE-2024-31212
MEDIUM
InstantCMS 2.16.2 - Authenticated SQL Injection via index_chart_data period Parameter
CVSS 6.7
CVE-2024-29008
MEDIUM
Apache CloudStack 4.14.0.0-4.18.1.0 - Unauthenticated Host Device Attachment via Extraconfig Feature
CVSS 6.4
CVE-2024-2689
MEDIUM
Temporal Server <1.20.5, 1.21.6, 1.22.7 - DoS
CVSS 4.4
CVE-2024-20334
MEDIUM
Cisco TelePresence Management Suite - XSS
CVSS 5.5
CVE-2024-27201
MEDIUM
Open Automation Software OAS Platform <19.00.0057 - Info Disclosure
CVSS 4.9
CVE-2024-27254
MEDIUM
IBM Db2 10.5, 11.1, 11.5 - Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2024-25046
MEDIUM
IBM Db2 11.1 and 11.5 - Authenticated Denial of Service via Specially Crafted Query
CVSS 5.3
Details
Vulnerabilities
12,465
Exploit Likelihood
High