CWE-707

Improper Neutralization

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

251 vulnerabilities with CWE-707
CVE-2025-27712 MEDIUM
Intel(R) Neural Compressor <v3.4 - Privilege Escalation
CVSS 5.7
CVE-2025-11445 MEDIUM
Kilo Code < 4.86.0 - Remote Code Execution via Prompt Handler
CVSS 6.3
CVE-2025-9797 LOW
mrvautin expressCart <b31302f4e99c3293bd742c6d076a721e168118b0 - Co...
CVSS 2.4
CVE-2025-24921 MEDIUM
Intel(R) Tiber(TM) Edge Platform <24.11.1 - Info Disclosure
CVSS 6.6
CVE-2025-3805 MEDIUM
sarrionandia tournatrack - Code Injection
CVSS 5.3
CVE-2025-3804 MEDIUM
thautwarm vscode-diana 0.0.1 - Code Injection
CVSS 5.3
CVE-2025-26633 HIGH KEV
Microsoft Management Console - Auth Bypass
CVSS 7.0
CVE-2025-1611 MEDIUM
ShopXO < 6.4.0 - Remote Code Execution in Template Handler
CVSS 4.7
CVE-2025-0697 MEDIUM
Telstra Smart Modem Gen 2 <20250115 - Code Injection
CVSS 5.3
CVE-2024-10915 HIGH
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via group Parameter
CVSS 8.1
CVE-2024-10914 HIGH
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via cgi_user_add name Parameter
CVSS 8.1
CVE-2024-10845 HIGH
Bookstore Management System 1.0 - SQL Injection via book_detail.php id Parameter
CVSS 7.3
CVE-2024-10844 HIGH
Bookstore Management System 1.0 - SQL Injection via search.php s Parameter
CVSS 7.3
CVE-2024-10842 LOW
romadebrian WEB-Sekolah 1.0 - Cross-Site Scripting via Username_Baru/Password Parameter
CVSS 2.4
CVE-2024-10841 MEDIUM
romadebrian WEB-Sekolah 1.0 - SQL Injection via Name Parameter in Mail Handler
CVSS 5.5
CVE-2024-10840 LOW
romadebrian WEB-Sekolah 1.0 - Cross-Site Scripting via kode Parameter in Backend
CVSS 2.4
CVE-2024-10810 MEDIUM
E-Health Care System 1.0 - SQL Injection via Doctor/app_request.php app_id Parameter
CVSS 6.3
CVE-2024-10809 MEDIUM
E-Health Care System 1.0 - SQL Injection via Doctor Chat Name/Message Parameter
CVSS 6.3
CVE-2024-10808 MEDIUM
E-Health Care System 1.0 - SQL Injection via Admin/req_detail.php id Parameter
CVSS 6.3
CVE-2024-10807 LOW
Hospital Management System 4.0 - Cross-Site Scripting via searchdata Parameter
CVSS 2.4
CVE-2024-10806 LOW
Hospital Management System 4.0 - Cross-Site Scripting via betweendates-detailsreports.php fromdate/todate Parameters
CVSS 2.4
CVE-2024-10805 MEDIUM
University Event Management System 1.0 - SQL Injection via doedit.php id Parameter
CVSS 6.3
CVE-2024-10791 HIGH
Codezips Hospital Appointment System 1.0 - SQL Injection via Name Parameter in doctorAction.php
CVSS 7.3
CVE-2024-10768 LOW
PHPGurukul Online Shopping Portal 2.0 - Cross-Site Scripting in two_tables.php
CVSS 3.5
CVE-2024-10752 HIGH
Codezips Pet Shop Management System 1.0 - SQL Injection via /productsadd.php id/name Parameter
CVSS 7.3
Details
Vulnerabilities 251