CWE-807

High likelihood

Reliance on Untrusted Inputs in a Security Decision

Parent: CWE-693 - Protection Mechanism Failure

The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

85 vulnerabilities with CWE-807
CVE-2021-36777 HIGH
openSUSE Build service <dc000cdfe9b9b715fb92195b1a57559362f689ef - ...
CVSS 8.1
CVE-2021-41129 HIGH
Pterodactyl Panel 1.0.0-1.6.1 - Authentication Bypass via Two-Factor Confirmation Token Manipulation
CVSS 8.1
CVE-2021-31999 HIGH
Rancher <2.5.9, <2.4.16 - Privilege Escalation
CVSS 8.8
CVE-2021-29479 HIGH
Ratpack < 1.9.0 - Cache Poisoning via X-Forwarded-Host Header
CVSS 7.0
CVE-2020-5252 MEDIUM
safety < 1.8.6 and < 1.9.0 - Reliance on Untrusted Inputs in Security Decision
CVSS 5.0
CVE-2019-25711 MEDIUM
SpotFTP Password Recover 2.4.2 Denial of Service via Name Field
CVSS 6.2
CVE-2019-25621 MEDIUM
Pixel Studio 2.17 Denial of Service via Malformed Input
CVSS 6.2
CVE-2019-25594 MEDIUM
ASPRunner.NET 10.1 Denial of Service via Table Name Field
CVSS 6.2
CVE-2019-25544 MEDIUM
Pidgin 2.13.0 Denial of Service via Malformed Username
CVSS 6.2
CVE-2017-0887 MEDIUM
Nextcloud Server <9.0.55,10.0.2 - Auth Bypass
CVSS 4.3
Details
Vulnerabilities 85
Exploit Likelihood High