CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2024-22360 MEDIUM
IBM Db2 11.5 - Denial of Service via Crafted Query on Columnar Tables
CVSS 5.3
CVE-2024-29074 MEDIUM
OpenHarmony < 3.2.4 - Arbitrary Code Execution via Improper Input Validation
CVSS 6.5
CVE-2024-28226 HIGH
OpenHarmony 3.2-4.0 - Denial of Service via Improper Input Validation
CVSS 8.1
CVE-2024-21473 CRITICAL
Qualcomm AR8035 Firmware - Memory Corruption via Log File Redirection
CVSS 9.8
CVE-2024-21453 HIGH
Qualcomm C-V2X 9150 Firmware - Denial of Service via Oversized Message Decoding
CVSS 7.5
CVE-2024-21452 HIGH
Qualcomm C-V2X 9150 Firmware - Denial of Service via ASN.1 OER Message Decoding
CVSS 7.3
CVE-2024-29946 HIGH
Splunk Enterprise <9.2.1, 9.1.4, 9.0.9 - Info Disclosure
CVSS 8.1
CVE-2024-20271 HIGH
Cisco IOS XE, Business APs, WLC - DoS via IPv4 Packet Processing
CVSS 8.6
CVE-2024-23482 HIGH
ZScaler Client Connector < 4.2.0.241 - Local Privilege Escalation via ZScalerService Process
CVSS 7.0
CVE-2024-2427 HIGH
Rockwell Automation PowerFlex 527 - DoS
CVSS 7.5
CVE-2024-2426 HIGH
Rockwell Automation PowerFlex 527 - DoS
CVSS 7.5
CVE-2024-2425 HIGH
Rockwell Automation PowerFlex 527 - DoS
CVSS 7.5
CVE-2024-29042 MEDIUM
francisco/translate < 3.0.0 - Cache Poisoning via opt.id Parameter
CVSS 5.3
CVE-2024-27932 MEDIUM
Deno 1.8.0-1.40.3 - Auth Token Leak via Improper Hostname Validation
CVSS 4.6
CVE-2024-27918 HIGH
Coder < 2.6.1, 2.7.0-2.7.2, 2.8.0-2.8.3 - OIDC Email Domain Verification Bypass
CVSS 8.2
CVE-2024-2469 HIGH
GitHub Enterprise Server >=3.8.0 - RCE
CVSS 8.0
CVE-2024-2443 CRITICAL
GitHub Enterprise Server <3.13 - Command Injection
CVSS 9.1
CVE-2024-23634 MEDIUM
GeoServer < 2.23.5 and 2.24.2 - Authenticated Arbitrary File Renaming via REST Coverage Store or Data Store API
CVSS 6.0
CVE-2024-24683 MEDIUM
Apache Hop Engine <2.8.0 - Info Disclosure
CVSS 6.5
CVE-2024-25942 MEDIUM
Dell PowerEdge Server BIOS < 2.19.0 - Arbitrary SMRAM Write via Improper SMM Verification
CVSS 4.4
CVE-2024-28855 HIGH
ZITADEL < 2.41.15 - Cross-Site Scripting in Login UI via Unsanitized Input Parameters
CVSS 8.1
CVE-2024-25656 MEDIUM
AVSystem UMP 23.07.0.16567~LTS - Info Disclosure
CVSS 5.9
CVE-2024-20327 HIGH
Cisco IOS XR < 7.9.21 - Unauthenticated Denial of Service via Malformed PPPoE Packet
CVSS 7.4
CVE-2024-20318 HIGH
Cisco IOS XR Software DoS via Layer 2 Ethernet Frame Handling
CVSS 7.4
CVE-2024-24549 HIGH
Apache Tomcat <11.0.0-M16, <10.1.18, <9.0.85, <=8.5.98 - DoS
CVSS 7.5
Details
Vulnerabilities 12,465
Exploit Likelihood High