CWE-20
12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,815)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Brocade 11Adx Bigiron RxFastiron+8 moreApr 29, 2026 Jan 23, 2014 N/A· v4 N/A· v3 5.4 MEDIUM· v2 The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remo...Show more |
The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage) via LDP discovery traffic containing malformed Hello messages, aka Bu...Show more |
1Cisco 2Telepresence Video Communication Server Software Telepresence Video Communication Servers SoftwareApr 29, 2026 Jan 22, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632. |
1Cisco 1Telepresence Isdn Gateway Software Apr 29, 2026 Jan 22, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a crafted Q.931 STATUS message, aka Bug ID CSCui50360. |
Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749. |
1Dell 3Powerconnect 3348 Powerconnect 3524pPowerconnect 5324Apr 29, 2026 Jan 20, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The login page in the GoAhead web server on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device outage) via a long username. |
1Dell 3Powerconnect 3348 Powerconnect 3524pPowerconnect 5324Apr 29, 2026 Jan 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticated users to cause a denial of service (device reset) via a direct reques...Show more |
1Dell 3Powerconnect 3348 Powerconnect 3524pPowerconnect 5324Apr 29, 2026 Jan 20, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device reset) or possibly execute arbitrary code by sending many packets...Show more |
2Apache Redhat3Jboss Enterprise Application Platform Jboss Enterprise Portal PlatformTomcatApr 29, 2026 Jan 19, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary...Show more |
2Canonical Httplib2 Project2Httplib2 Ubuntu LinuxApr 29, 2026 Jan 18, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, wh...Show more |
IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services end...Show more |
The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this interface, aka Bug ID CSCue65962. |
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload. |
Microsoft Dynamics AX 4.0 SP2, 2009 SP1, 2012, and 2012 R2 allows remote authenticated users to cause a denial of service (instance outage) via crafted data to an Application Object Server (AOS) instance, aka "Query Filt...Show more |
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory...Show more |
2Codeaurora Qualcomm2Android Msm Quic Mobile Station Modem KernelApr 29, 2026 Jan 14, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Multiple array index errors in drivers/media/video/msm/server/msm_cam_server.c in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and oth...Show more |
1Conceptronic 2C54apm C54apm FirmwareApr 29, 2026 Jan 10, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks...Show more |
1Conceptronic 2C54apm C54apm FirmwareApr 29, 2026 Jan 10, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the submit-url pa...Show more |
1Cisco 3Unified Ip Phone 9951 Unified Ip Phone 9971Unified Ip Phones 9900 Series FirmwareApr 29, 2026 Jan 10, 2014 N/A· v4 N/A· v3 5.4 MEDIUM· v2 Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898. |
1Ibm 4Atlas Ediscovery Process Management Atlas SuiteDisposal And Governance Management For It+1 moreApr 29, 2026 Jan 10, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and...Show more |