CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,465 vulnerabilities with CWE-20
CVE-2024-20017 CRITICAL
MediaTek WLAN Service - Zero-Click Remote Code Execution
CVSS 9.8
CVE-2024-25016 HIGH
IBM MQ 9.0.0.0-9.0.0.22 & MQ Appliance 9.3.0.0-9.3.4.9 - DoS via Buffering Logic
CVSS 7.5
CVE-2024-27092 MEDIUM
Hoppscotch <2023.12.5 - Info Disclosure
CVSS 5.4
CVE-2024-27093 MEDIUM
Minder < 0.0.31 - Denial of Service via Invalid Repository Upstream ID
CVSS 4.6
CVE-2024-27447 CRITICAL
pretix < 2024.1.1 - Improper Input Validation
CVSS 9.8
CVE-2024-23320 HIGH
Apache DolphinScheduler < 3.2.1 - Authenticated Remote Code Execution via JavaScript Injection
CVSS 8.8
CVE-2024-26151 HIGH
mjml-python 0.10.0-0.10.9 - Cross-Site Scripting via Unsanitized Template Input
CVSS 8.2
CVE-2024-1714 HIGH
SailPoint IdentityIQ - Authenticated Access Request Bypass via Entitlement Whitespace Handling
CVSS 7.1
CVE-2024-22054 HIGH
UniFi Devices < 6.6.61 DoS via Malformed Discovery Packet
CVSS 7.5
CVE-2024-25974 MEDIUM
OpenOlat < 18.1.6 - Authenticated Stored Cross-Site Scripting via SVG Upload
CVSS 5.4
CVE-2024-25973 MEDIUM
OpenOlat < 18.1.6 - Stored Cross-Site Scripting via Group/Catalog/Curriculum Name Fields
CVSS 5.4
CVE-2024-1638 HIGH
Zephyr < 3.5.0 - Improper Input Validation in Bluetooth LE Secure Connection Permission Checks
CVSS 8.2
CVE-2024-0021 HIGH
Android - Local Privilege Escalation via Notification Listener Logic Error
CVSS 7.8
CVE-2024-0031 CRITICAL
Android - Remote Code Execution via Improper Input Validation in attp_build_read_by_type_value_cmd
CVSS 9.8
CVE-2024-20733 MEDIUM
Acrobat Reader <20.005.30539-23.008.20470 - DoS
CVSS 5.5
CVE-2024-1471 MEDIUM
Tenable Security Center < 6.3.0 - Authenticated HTML Injection via Repository Parameters
CVSS 5.9
CVE-2024-24696 MEDIUM
Zoom Desktop Client/VDI Client/Meeting SDK - Info Disclosure
CVSS 6.8
CVE-2024-24695 MEDIUM
Zoom Desktop Client for Windows - Info Disclosure
CVSS 6.8
CVE-2024-1378 CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Nomad SMTP Template
CVSS 9.1
CVE-2024-1374 CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Nomad Templates
CVSS 9.1
CVE-2024-1372 CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via SAML Settings
CVSS 9.1
CVE-2024-1369 CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Management Console Collectd Configuration
CVSS 9.1
CVE-2024-1359 CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via HTTP Proxy Setup
CVSS 9.1
CVE-2024-1355 CRITICAL
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via Management Console Service URL
CVSS 9.1
CVE-2024-1354 HIGH
GitHub Enterprise Server < 3.8.15 - Authenticated Command Injection via syslog-ng Configuration
CVSS 8.0
Details
Vulnerabilities 12,465
Exploit Likelihood High