CWE-20 · 13 033 записей
Improper Input Validation
CVE этого класса
10 000 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
100Срочно | CVE-2024-3400Готовый эксплойт | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Критическая10,0 | KEV | 100,0 % | 12 апр. 2024 г. |
99Срочно | CVE-2018-7600Готовый эксплойт | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because odrupal · drupal · CWE-20 | Критическая9,8 | KEV | 100,0 % | 29 мар. 2018 г. |
99Срочно | CVE-2019-0604Готовый эксплойт | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pamicrosoft · sharepoint enterprise server · CWE-20 | Критическая9,8 | KEV | 99,9 % | 5 мар. 2019 г. |
99Срочно | CVE-2022-47966Готовый эксплойт | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Sanzohocorp · manageengine access manager plus · CWE-20 | Критическая9,8 | KEV | 99,8 % | 18 янв. 2023 г. |
99Срочно | CVE-2018-0171Готовый эксплойт | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attackercisco · ios · CWE-20 | Критическая9,8 | KEV | 99,5 % | 28 мар. 2018 г. |
99Срочно | CVE-2022-24086Готовый эксплойт | Adobe Commerce checkout improper input validation leads to remote code executionadobe · commerce · CWE-20 | Критическая9,8 | KEV | 99,2 % | 16 февр. 2022 г. |
99Срочно | CVE-2023-22515Готовый эксплойт | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknowatlassian · confluence data center · CWE-20 | Критическая9,8 | KEV | 99,2 % | 4 окт. 2023 г. |
99Срочно | CVE-2017-3881Готовый эксплойт | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthecisco · ios · CWE-20 | Критическая9,8 | KEV | 99,0 % | 17 мар. 2017 г. |
99Срочно | CVE-2017-9791Готовый эксплойт | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message tapache · struts · CWE-20 | Критическая9,8 | KEV | 98,9 % | 10 июл. 2017 г. |
99Срочно | CVE-2020-1350Готовый эксплойт | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows microsoft · windows server 2008 · CWE-20 | Критическая10,0 | KEV | 96,7 % | 14 июл. 2020 г. |
98Срочно | CVE-2017-15944Готовый эксплойт | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to executepaloaltonetworks · pan-os · CWE-20 | Критическая9,8 | KEV | 98,3 % | 11 дек. 2017 г. |
98Срочно | CVE-2023-23397Готовый эксплойт | Microsoft Outlook Elevation of Privilege Vulnerabilitymicrosoft · 365 apps · CWE-20 | Критическая9,8 | KEV | 97,2 % | 14 мар. 2023 г. |
97Срочно | CVE-2024-21413Готовый эксплойт | Microsoft Outlook Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-20 | Критическая9,8 | KEV | 94,7 % | 13 февр. 2024 г. |
95Срочно | CVE-2023-2868Готовый эксплойт | Remote Code injection in Barracuda Email Security Gatewaybarracuda · email security gateway 300 firmware · CWE-20 | Критическая9,8 | KEV | 87,7 % | 24 мая 2023 г. |
94Срочно | CVE-2009-0927Готовый эксплойт | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to eadobe · acrobat reader · CWE-20 | Высокая8,8 | KEV | 96,6 % | 19 мар. 2009 г. |
94Срочно | CVE-2025-54236Готовый эксплойт | Adobe Commerce | Improper Input Validation (CWE-20)adobe · commerce · CWE-20 | Критическая9,1 | KEV | 94,5 % | 9 сент. 2025 г. |
94Срочно | CVE-2020-3161Готовый эксплойт | Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerabilitycisco · ip phone 8865 firmware · CWE-20 | Критическая9,8 | KEV | 83,9 % | 15 апр. 2020 г. |
92Срочно | CVE-2017-0148Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block · CWE-20 | Высокая8,1 | KEV | 99,4 % | 16 мар. 2017 г. |
92Срочно | CVE-2016-3714Готовый эксплойт | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | Высокая8,4 | KEV | 97,5 % | 5 мая 2016 г. |
90Срочно | CVE-2020-3452Готовый эксплойт | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerabilitycisco · adaptive security appliance software · CWE-20 | Высокая7,5 | KEV | 100,0 % | 22 июл. 2020 г. |
90Срочно | CVE-2018-0296Готовый эксплойт | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to causecisco · adaptive security appliance software · CWE-20 | Высокая7,5 | KEV | 99,9 % | 7 июн. 2018 г. |
89Срочно | CVE-2023-22952Готовый эксплойт | In SugarCRM before 12.0.sugarcrm · sugarcrm · CWE-20 | Высокая8,8 | KEV | 80,1 % | 11 янв. 2023 г. |
87Срочно | CVE-2019-1652Готовый эксплойт | Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerabilitycisco · rv320 firmware · CWE-20 | Высокая7,2 | KEV | 95,9 % | 24 янв. 2019 г. |
87Срочно | CVE-2012-0151Готовый эксплойт | The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Semicrosoft · windows 7 · CWE-20 | Высокая7,8 | KEV | 87,7 % | 10 апр. 2012 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2024-3400100Срочно
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %paloaltonetworks · pan-os12 апр. 2024 г.
- CVE-2018-760099Срочно
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %drupal · drupal29 мар. 2018 г.
- CVE-2019-060499Срочно
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint enterprise server5 мар. 2019 г.
- CVE-2022-4796699Срочно
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zohocorp · manageengine access manager plus18 янв. 2023 г.
- CVE-2018-017199Срочно
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %cisco · ios28 мар. 2018 г.
- CVE-2022-2408699Срочно
Adobe Commerce checkout improper input validation leads to remote code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · commerce16 февр. 2022 г.
- CVE-2023-2251599Срочно
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %atlassian · confluence data center4 окт. 2023 г.
- CVE-2017-388199Срочно
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %cisco · ios17 мар. 2017 г.
- CVE-2017-979199Срочно
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · struts10 июл. 2017 г.
- CVE-2020-135099Срочно
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 97 %microsoft · windows server 200814 июл. 2020 г.
- CVE-2017-1594498Срочно
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %paloaltonetworks · pan-os11 дек. 2017 г.
- CVE-2023-2339798Срочно
Microsoft Outlook Elevation of Privilege Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %microsoft · 365 apps14 мар. 2023 г.
- CVE-2024-2141397Срочно
Microsoft Outlook Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %microsoft · 365 apps13 февр. 2024 г.
- CVE-2023-286895Срочно
Remote Code injection in Barracuda Email Security Gateway
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 88 %barracuda · email security gateway 300 firmware24 мая 2023 г.
- CVE-2009-092794Срочно
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to e
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 97 %adobe · acrobat reader19 мар. 2009 г.
- CVE-2025-5423694Срочно
Adobe Commerce | Improper Input Validation (CWE-20)
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 95 %adobe · commerce9 сент. 2025 г.
- CVE-2020-316194Срочно
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %cisco · ip phone 8865 firmware15 апр. 2020 г.
- CVE-2017-014892Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 99 %microsoft · server message block16 мар. 2017 г.
- CVE-2016-371492Срочно
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 97 %imagemagick · imagemagick5 мая 2016 г.
- CVE-2020-345290Срочно
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %cisco · adaptive security appliance software22 июл. 2020 г.
- CVE-2018-029690Срочно
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %cisco · adaptive security appliance software7 июн. 2018 г.
- CVE-2023-2295289Срочно
In SugarCRM before 12.0.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 80 %sugarcrm · sugarcrm11 янв. 2023 г.
- CVE-2019-165287Срочно
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 96 %cisco · rv320 firmware24 янв. 2019 г.
- CVE-2012-015187Срочно
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 88 %microsoft · windows 710 апр. 2012 г.