The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,465 vulnerabilities with CWE-20
CVE-2024-20017
CRITICAL
MediaTek WLAN Service - Zero-Click Remote Code Execution
CVSS 9.8
CVE-2024-25016
HIGH
IBM MQ 9.0.0.0-9.0.0.22 & MQ Appliance 9.3.0.0-9.3.4.9 - DoS via Buffering Logic
CVSS 7.5
CVE-2024-27092
MEDIUM
Hoppscotch <2023.12.5 - Info Disclosure
CVSS 5.4
CVE-2024-27093
MEDIUM
Minder < 0.0.31 - Denial of Service via Invalid Repository Upstream ID
CVSS 4.6
CVE-2024-27447
CRITICAL
pretix < 2024.1.1 - Improper Input Validation
CVSS 9.8
CVE-2024-23320
HIGH
Apache DolphinScheduler < 3.2.1 - Authenticated Remote Code Execution via JavaScript Injection
CVSS 8.8
CVE-2024-26151
HIGH
mjml-python 0.10.0-0.10.9 - Cross-Site Scripting via Unsanitized Template Input
CVSS 8.2
CVE-2024-1714
HIGH
SailPoint IdentityIQ - Authenticated Access Request Bypass via Entitlement Whitespace Handling
CVSS 7.1
CVE-2024-22054
HIGH
UniFi Devices < 6.6.61 DoS via Malformed Discovery Packet
CVSS 7.5
CVE-2024-25974
MEDIUM
OpenOlat < 18.1.6 - Authenticated Stored Cross-Site Scripting via SVG Upload
CVSS 5.4
CVE-2024-25973
MEDIUM
OpenOlat < 18.1.6 - Stored Cross-Site Scripting via Group/Catalog/Curriculum Name Fields
CVSS 5.4
CVE-2024-1638
HIGH
Zephyr < 3.5.0 - Improper Input Validation in Bluetooth LE Secure Connection Permission Checks
CVSS 8.2
CVE-2024-0021
HIGH
Android - Local Privilege Escalation via Notification Listener Logic Error
CVSS 7.8
CVE-2024-0031
CRITICAL
Android - Remote Code Execution via Improper Input Validation in attp_build_read_by_type_value_cmd
CVSS 9.8
CVE-2024-20733
MEDIUM
Acrobat Reader <20.005.30539-23.008.20470 - DoS
CVSS 5.5
CVE-2024-1471
MEDIUM
Tenable Security Center < 6.3.0 - Authenticated HTML Injection via Repository Parameters
CVSS 5.9
CVE-2024-24696
MEDIUM
Zoom Desktop Client/VDI Client/Meeting SDK - Info Disclosure
CVSS 6.8
CVE-2024-24695
MEDIUM
Zoom Desktop Client for Windows - Info Disclosure
CVSS 6.8
CVE-2024-1378
CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Nomad SMTP Template
CVSS 9.1
CVE-2024-1374
CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Nomad Templates
CVSS 9.1
CVE-2024-1372
CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via SAML Settings
CVSS 9.1
CVE-2024-1369
CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Management Console Collectd Configuration
CVSS 9.1
CVE-2024-1359
CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via HTTP Proxy Setup
CVSS 9.1
CVE-2024-1355
CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Management Console Service URL
CVSS 9.1
CVE-2024-1354
HIGH
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via syslog-ng Configuration
CVSS 8.0
Details
Vulnerabilities
12,465
Exploit Likelihood
High