İçeriğe atla
Noroxi

CWE-20 · 13.033 kayıt

Improper Input Validation

Bu sınıftaki CVE’ler

10.000 kayıt

  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    apache · log4j10 Ara 2021

  • PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    paloaltonetworks · pan-os12 Nis 2024

  • Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    drupal · drupal29 Mar 2018

  • A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · sharepoint enterprise server5 Mar 2019

  • Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    zohocorp · manageengine access manager plus18 Oca 2023

  • A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    cisco · ios28 Mar 2018

  • Adobe Commerce checkout improper input validation leads to remote code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    adobe · commerce16 Şub 2022

  • Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    atlassian · confluence data center4 Eki 2023

  • A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    cisco · ios17 Mar 2017

  • The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · struts10 Tem 2017

  • A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %97

    microsoft · windows server 200814 Tem 2020

  • Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    paloaltonetworks · pan-os11 Ara 2017

  • Microsoft Outlook Elevation of Privilege Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    microsoft · 365 apps14 Mar 2023

  • Microsoft Outlook Remote Code Execution Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    microsoft · 365 apps13 Şub 2024

  • Remote Code injection in Barracuda Email Security Gateway

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %88

    barracuda · email security gateway 300 firmware24 May 2023

  • Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to e

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97

    adobe · acrobat reader19 Mar 2009

  • Adobe Commerce | Improper Input Validation (CWE-20)

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %95

    adobe · commerce9 Eyl 2025

  • Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84

    cisco · ip phone 8865 firmware15 Nis 2020

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %99

    microsoft · server message block16 Mar 2017

  • The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor

    YüksekCVSS 8,4KEVSilahlaştırılmışEPSS %97

    imagemagick · imagemagick5 May 2016

  • Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    cisco · adaptive security appliance software22 Tem 2020

  • A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    cisco · adaptive security appliance software7 Haz 2018

  • In SugarCRM before 12.0.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %80

    sugarcrm · sugarcrm11 Oca 2023

  • Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %96

    cisco · rv320 firmware24 Oca 2019

  • The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %88

    microsoft · windows 710 Nis 2012

Tüm zafiyet sınıfları