Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-20 (输入验证不恰当) — Vulnerability Class 3267

3267 vulnerabilities classified as CWE-20 (输入验证不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-29831 Apache DolphinScheduler: RCE by arbitrary js execution — Apache DolphinScheduler 8.2AIHighAI2024-08-09
CVE-2024-7512 Concrete CMS Stored XSS in Board instances — Concrete CMS 4.8AIMediumAI2024-08-09
CVE-2024-6254 Brizy – Page Builder <= 2.5.1 - Cross-Site Request Forgery — Brizy – Page Builder 4.3 Medium2024-08-08
CVE-2024-7005 Google Chrome 安全漏洞 — Chrome 6.5AIMediumAI2024-08-06
CVE-2024-7004 Google Chrome 安全漏洞 — Chrome 6.5AIMediumAI2024-08-06
CVE-2024-23483 Local Privilege Escalation via lack of input validation — Client Connector 7.0 High2024-08-06
CVE-2024-6915 JFrog Artifactory Cache Poisoning — Artifactory 9.3 Critical2024-08-05
CVE-2024-21978 AMD SEV-SNP 安全漏洞 — 3rd Gen AMD EPYC™ Processors 6.0 Medium2024-08-05
CVE-2024-38879 Siemens Omnivise T3000 输入验证错误漏洞 — Omnivise T3000 Application Server R9.2 7.5 High2024-08-02
CVE-2024-40721 CHANGING Information Technology TCBServiSign Windows Version - Improper Input Validation — TCBServiSign Windows Version 8.8 High2024-08-02
CVE-2024-40720 CHANGING Information Technology TCBServiSign Windows Version - Improper Input Validation — TCBServiSign Windows Version 8.8 High2024-08-02
CVE-2024-4353 Stored XSS in Generate Board Name Input Field — Concrete CMS 4.8AIMediumAI2024-08-01
CVE-2024-23600 PingIDM Query Filter Vulnerability — PingIDM 2.7 Low2024-08-01
CVE-2017-3772 Lenovo PC Manager 安全漏洞 — PC Manager 5.5 Medium2024-07-31
CVE-2023-1577 Lenovo Driver Manager 安全漏洞 — Driver Manager 7.8 High2024-07-31
CVE-2024-6978 Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users — SDP Client 5.6 Medium2024-07-31
CVE-2024-6973 Remote Code Execution in Cato Windows SDP client via crafted URLs — SDP Client 7.5 High2024-07-31
CVE-2024-41945 The fuels-ts typescript SDK has no awareness of to-be-spent transactions — fuels-ts 3.1 Low2024-07-30
CVE-2024-5969 AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sending — Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit 5.8 Medium2024-07-27
CVE-2024-41120 streamlit-geospatial blind SSRF in pages/9_🔲_Vector_Data_Visualization.py — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-41119 streamlit-geospatial remote code execution in pages/8_🏜️_Raster_Data_Visualization.py — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-41117 Remote code execution in streamlit geospatial in pages/10_🌍_Earth_Engine_Datasets.py — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-41116 Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py MODIS Ocean Color SMI option vis_params — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-41115 Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py MODIS Ocean Color SMI option palette — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-41114 Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py MODIS Gap filled Land Surface Temperature Daily option — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-41113 Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py Any Earth Engine ImageCollection option vis_params — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-41112 Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py Any Earth Engine ImageCollection option palette — streamlit-geospatial 9.8 Critical2024-07-26
CVE-2024-35296 Apache Traffic Server: Invalid Accept-Encoding can force forwarding requests — Apache Traffic Server 5.3 -2024-07-26
CVE-2024-25090 Apache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode — Apache Roller 5.4 -2024-07-26
CVE-2024-3938 DotCMS 安全漏洞 — dotCMS core 5.4 Medium2024-07-25

Vulnerabilities classified as CWE-20 (输入验证不恰当) represent 3267 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.