The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,465 vulnerabilities with CWE-20
CVE-2024-1854
MEDIUM
Essential Blocks < 4.5.1 - Authenticated Stored Cross-Site Scripting via blockId Parameter
CVSS 6.4
CVE-2024-0161
HIGH
Dell PowerEdge Server BIOS - Arbitrary SMRAM Write via Improper SMM Communication Buffer Verification
CVSS 7.2
CVE-2024-27894
HIGH
Pulsar Functions Worker - Code Injection
CVSS 8.5
CVE-2024-27135
HIGH
Apache Pulsar 2.4.0-2.10.5, 2.11.0-2.11.3, 3.0.0-3.0.2, 3.1.0-3.1.2, 3.2.0 - Remote Code Execution
CVSS 8.5
CVE-2024-26197
MEDIUM
Windows Server 2012, 2016, 2019, 2022 DoS in Standards-Based Storage Management Service
CVSS 6.5
CVE-2024-26181
MEDIUM
Windows Kernel - Denial of Service via Improper Input Validation
CVSS 5.5
CVE-2024-26173
HIGH
Windows Kernel - Elevation of Privilege via Improper Input Validation
CVSS 7.8
CVE-2024-26170
HIGH
Windows 10/11, Server 2022 Elevation of Privilege in Composite Image File System
CVSS 7.8
CVE-2024-26164
HIGH
Microsoft Django Backend for SQL Server < 1.4.1 - Remote Code Execution
CVSS 8.8
CVE-2024-21448
MEDIUM
Microsoft Teams < 1.0.0.2024022302 - Information Disclosure
CVSS 5.0
CVE-2024-26002
HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Privilege Escalation via Qualcom plctool File Ownership Change
CVSS 7.8
CVE-2024-25999
HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Unauthenticated Privilege Escalation via OCPP Agent Service
CVSS 8.4
CVE-2024-25997
MEDIUM
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Unauthenticated Log Injection via Improper Input Validation
CVSS 5.3
CVE-2024-25995
CRITICAL
PHOENIX CONTACT CHARX SEC-3000/3050/3100/3150 < 1.5.1 - RCE & DoS via Input Validation
CVSS 9.8
CVE-2024-23717
HIGH
Android - Keystroke Injection via Improper Input Validation in btm_sec.cc
CVSS 8.8
CVE-2024-0045
MEDIUM
Android - Out-of-bounds Read in smp_proc_sec_req
CVSS 6.5
CVE-2024-2339
HIGH
PostgreSQL Anonymizer 1.2 - Privilege Escalation via Malicious Masking Function
CVSS 8.0
CVE-2024-27613
HIGH
Numbas editor <7.3 - Info Disclosure
CVSS 7.3
CVE-2024-27612
MEDIUM
Numbas editor <7.3 - Info Disclosure
CVSS 6.2
CVE-2024-23294
HIGH
macOS < 14.4 - Remote Code Execution
CVSS 7.8
CVE-2024-23263
MEDIUM
Safari < 17.4 - Content Security Policy Bypass via Malicious Web Content
CVSS 6.5
CVE-2024-23246
HIGH
iPadOS < 16.7.6 - Sandbox Escape via Improper Input Validation
CVSS 8.6
CVE-2024-1534
MEDIUM
Booster for WooCommerce <= 7.1.7 - Authenticated Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2024-27931
MEDIUM
Deno < 1.41.1 - Path Traversal via Temp File API Parameter Injection
CVSS 5.8
CVE-2024-20034
HIGH
Android - Local Privilege Escalation via Missing Bounds Check in Battery Component
CVSS 7.2
Details
Vulnerabilities
12,465
Exploit Likelihood
High