CWE-807
High likelihoodReliance on Untrusted Inputs in a Security Decision
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
85 vulnerabilities with CWE-807
CVE-2025-53882
MEDIUM
openSUSE mailman3 logrotate - Arbitrary Process Signal
CVSS 4.4
CVE-2025-49827
CRITICAL
Conjur 1.19.5-1.22.0 and 13.1-13.5 - IAM Authenticator Bypass via Malformed Regular Expression
CVSS 9.8
CVE-2025-0117
HIGH
GlobalProtect <unknown - Privilege Escalation
CVE-2025-1969
MEDIUM
AWS TEAM for IAM Identity Center < 1.2.2 - Request Spoofing via Input Validation Bypass
CVSS 4.3
CVE-2025-1126
CRITICAL
Lexmark Print Management Client - RCE
CVSS 9.3
CVE-2025-24369
LOW
Anubis < v1.11.0-37 - Client-Specified Difficulty Bot Protection Bypass
CVE-2024-13974
HIGH
Sophos Firewall < 21.0.1 - Remote Code Execution via Up2Date DNS Control
CVSS 8.1
CVE-2024-55354
HIGH
Lucee <5.4.7.3 LTS & 6 <6.1.1.118 - Code Injection
CVSS 8.8
CVE-2024-52327
MEDIUM
ECOVACS Home < 3.0.2 - Authenticated PIN Bypass for Live Video Feed Access
CVSS 6.5
CVE-2024-9310
MEDIUM
Software-Defined Radios - Info Disclosure
CVE-2024-45654
MEDIUM
IBM Security ReaQta 3.12 - Privilege Escalation
CVSS 4.3
CVE-2024-11146
MEDIUM
TrueFiling <3.1.112.19 - Info Disclosure
CVSS 6.3
CVE-2024-47254
MEDIUM
2N Access Commander <3.1.1.2 - Privilege Escalation
CVSS 6.3
CVE-2024-51561
HIGH
Aero < 120820241550 - Authenticated OTP Bypass via Response Manipulation
CVSS 7.5
CVE-2024-21510
MEDIUM
sinatra < 4.1.0 - Open Redirect via X-Forwarded-Host Header
CVSS 5.4
CVE-2024-5754
HIGH
BT Encryption procedure host - Info Disclosure
CVSS 8.2
CVE-2024-28829
HIGH
Checkmk <2.3.0p12-2.0.0 - Privilege Escalation
CVSS 7.8
CVE-2024-7005
MEDIUM
Google Chrome <127.0.6533.72 - Auth Bypass
CVSS 4.3
CVE-2024-29039
CRITICAL
tpm2-tools < 5.7 - Digest Mapping Manipulation via TPML_PCR_SELECTION Alteration
CVSS 9.0
CVE-2024-28824
HIGH
Checkmk <2.3.0b4-2.0.0 - Privilege Escalation
CVSS 8.8
CVE-2023-46686
MEDIUM
Gallagher Diagnostics Service <1.3.0 - Privilege Escalation
CVSS 5.5
CVE-2023-45128
CRITICAL
Fiber < 2.50.0 - Cross-Site Request Forgery via Improper CSRF Token Validation
CVSS 10.0
CVE-2023-0009
HIGH
Paloaltonetworks Palo Alto Networks GlobalProtect - Privilege Escalation
CVSS 7.8
CVE-2022-24400
HIGH
midnightblue tetra - Authorization Bypass via Predictable MS Challenge RAND2
CVSS 7.5
CVE-2022-20744
MEDIUM
Cisco Firepower Management Center - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
85
Exploit Likelihood
High