← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
9Asr 1001
Asr 1002Asr 1002 X+6 more
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
6.1 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software, when DHCPv6 replay is configured, allows remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 packet, aka Bug ID CSCun45520.
1Cisco
2Unified Contact Center Enterprise
Unified Contact Center Express Editor Software
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request,...Show more
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.Show less
1Xen
1Xen
May 6, 2026
Apr 28, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL po...Show more
The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) via unspecified vectors.Show less
1Gnustep
1Base
May 6, 2026
Apr 28, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an...Show more
Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an invalid request.Show less
1Zarafa
1Zarafa
May 6, 2026
Apr 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors relat...Show more
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."Show less
1Zarafa
1Zarafa
May 6, 2026
Apr 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the username."
1Net Snmp
1Net Snmp
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an emp...Show more
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.Show less
1Uclouvain
1Openjpeg
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.
1Litech
1Router Advertisement Daemon
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The router advertisement daemon (radvd) before 1.8.2 does not properly handle errors in the privsep_init function, which causes the radvd daemon to run as root and has an unspecified impact.
1Openstack
2Icehouse
Image Registry And Delivery Service (glance)
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to exe...Show more
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.Show less
1Uclouvain
1Openjpeg
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger NULL pointer dereferences, division-by-zero, and other errors.
1Google
1Chrome
May 6, 2026
Apr 26, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote atta...Show more
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.Show less
1Ddsn
1Cm3 Acora Content Management System
May 6, 2026
Apr 25, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing...Show more
Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the l parameter to track.aspx.Show less
1Cisco
9Asr 1001
Asr 1002Asr 1002 X+6 more
May 6, 2026
Apr 24, 2014
N/A· v4
N/A· v3
6.1 MEDIUM· v2
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentatio...Show more
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.Show less
1Samba
1Rsync
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.
2Opensuse
Otrs
2Opensuse
Otrs
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.
1Apple
1Mac Os X
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.
1Apple
1Mac Os X
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon exit) via ASN.1 data encountered in the Kerberos 5 protocol.
1Cisco
1Ios
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518.