← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
9.0 HIGH· v2
Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to internal system scripts, aka Bu...Show more
Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to internal system scripts, aka Bug ID CSCue60211.Show less
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCua86589.
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The SIP implementation in Cisco TelePresence TC Software 4.x and TE Software 4.x allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCto70562.
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCtq72699.
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCuj94651.
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCua64961.
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCud29566.
1Cisco
13Tandberg 2000 Mxp
Tandberg 550 MxpTandberg 770 Mxp+10 more
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCty45731.
1Cisco
13Tandberg 2000 Mxp
Tandberg 550 MxpTandberg 770 Mxp+10 more
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCty45745.
1Cisco
13Tandberg 2000 Mxp
Tandberg 550 MxpTandberg 770 Mxp+10 more
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCtq78722.
1Cisco
13Tandberg 2000 Mxp
Tandberg 550 MxpTandberg 770 Mxp+10 more
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45720.
1Cisco
13Tandberg 2000 Mxp
Tandberg 550 MxpTandberg 770 Mxp+10 more
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45733.
1Cisco
13Tandberg 2000 Mxp
Tandberg 550 MxpTandberg 770 Mxp+10 more
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45739.
1Transifex
1Transifex
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this...Show more
Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2073.Show less
1Transifex
1Transifex
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate.
1Apache
2Commons Beanutils
Struts
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which...Show more
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.Show less
1Simplemachines
1Simple Machines Forum
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
1Simplemachines
1Simple Machines Forum
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters.
1Simplemachines
1Simple Machines Forum
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.
1Cisco
1Unified Communications Manager
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCun74352.