CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2024-1854 MEDIUM
Essential Blocks < 4.5.1 - Authenticated Stored Cross-Site Scripting via blockId Parameter
CVSS 6.4
CVE-2024-0161 HIGH
Dell PowerEdge Server BIOS - Arbitrary SMRAM Write via Improper SMM Communication Buffer Verification
CVSS 7.2
CVE-2024-27894 HIGH
Pulsar Functions Worker - Code Injection
CVSS 8.5
CVE-2024-27135 HIGH
Apache Pulsar 2.4.0-2.10.5, 2.11.0-2.11.3, 3.0.0-3.0.2, 3.1.0-3.1.2, 3.2.0 - Remote Code Execution
CVSS 8.5
CVE-2024-26197 MEDIUM
Windows Server 2012, 2016, 2019, 2022 DoS in Standards-Based Storage Management Service
CVSS 6.5
CVE-2024-26181 MEDIUM
Windows Kernel - Denial of Service via Improper Input Validation
CVSS 5.5
CVE-2024-26173 HIGH
Windows Kernel - Elevation of Privilege via Improper Input Validation
CVSS 7.8
CVE-2024-26170 HIGH
Windows 10/11, Server 2022 Elevation of Privilege in Composite Image File System
CVSS 7.8
CVE-2024-26164 HIGH
Microsoft Django Backend for SQL Server < 1.4.1 - Remote Code Execution
CVSS 8.8
CVE-2024-21448 MEDIUM
Microsoft Teams < 1.0.0.2024022302 - Information Disclosure
CVSS 5.0
CVE-2024-26002 HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Privilege Escalation via Qualcom plctool File Ownership Change
CVSS 7.8
CVE-2024-25999 HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Unauthenticated Privilege Escalation via OCPP Agent Service
CVSS 8.4
CVE-2024-25997 MEDIUM
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Unauthenticated Log Injection via Improper Input Validation
CVSS 5.3
CVE-2024-25995 CRITICAL
PHOENIX CONTACT CHARX SEC-3000/3050/3100/3150 < 1.5.1 - RCE & DoS via Input Validation
CVSS 9.8
CVE-2024-23717 HIGH
Android - Keystroke Injection via Improper Input Validation in btm_sec.cc
CVSS 8.8
CVE-2024-0045 MEDIUM
Android - Out-of-bounds Read in smp_proc_sec_req
CVSS 6.5
CVE-2024-2339 HIGH
PostgreSQL Anonymizer 1.2 - Privilege Escalation via Malicious Masking Function
CVSS 8.0
CVE-2024-27613 HIGH
Numbas editor <7.3 - Info Disclosure
CVSS 7.3
CVE-2024-27612 MEDIUM
Numbas editor <7.3 - Info Disclosure
CVSS 6.2
CVE-2024-23294 HIGH
macOS < 14.4 - Remote Code Execution
CVSS 7.8
CVE-2024-23263 MEDIUM
Safari < 17.4 - Content Security Policy Bypass via Malicious Web Content
CVSS 6.5
CVE-2024-23246 HIGH
iPadOS < 16.7.6 - Sandbox Escape via Improper Input Validation
CVSS 8.6
CVE-2024-1534 MEDIUM
Booster for WooCommerce <= 7.1.7 - Authenticated Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2024-27931 MEDIUM
Deno < 1.41.1 - Path Traversal via Temp File API Parameter Injection
CVSS 5.8
CVE-2024-20034 HIGH
Android - Local Privilege Escalation via Missing Bounds Check in Battery Component
CVSS 7.2
Details
Vulnerabilities 12,465
Exploit Likelihood High