CWE-20
12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,815)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Barebones 3Bbedit TextwranglerYojimboApr 29, 2026 Dec 31, 2013 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attacke...Show more |
1Hot 2Hotbox Router Hotbox Router FirmwareApr 29, 2026 Dec 30, 2013 N/A· v4 N/A· v3 6.1 MEDIUM· v2 goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data. |
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav. |
Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709. |
Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/admin/ in the OptimizePress theme before 1.61 for WordPress allow remote...Show more |
Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and...Show more |
3Canonical DebianHaxx3Debian Linux LibcurlUbuntu LinuxApr 29, 2026 Dec 23, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it e...Show more |
QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack. |
Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php. |
The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL. |
1Ibm 2Sterling B2b Integrator Sterling File GatewayApr 29, 2026 Dec 21, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors. |
1Ibm 2Sterling B2b Integrator Sterling File GatewayApr 29, 2026 Dec 21, 2013 N/A· v4 N/A· v3 4.9 MEDIUM· v2 IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information...Show more |
1Ibm 1Spss Collaboration And Deployment Services Apr 29, 2026 Dec 21, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via...Show more |
1Novatech 6Orion5 Dnp Master Orion5 Dnp SlaveOrion5r Dnp Master+3 moreApr 29, 2026 Dec 21, 2013 N/A· v4 N/A· v3 4.7 MEDIUM· v2 NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to c...Show more |
1Novatech 6Orion5 Dnp Master Orion5 Dnp SlaveOrion5r Dnp Master+3 moreApr 29, 2026 Dec 21, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial...Show more |
epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafte...Show more |
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a deni...Show more |
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via v...Show more |
1Cisco 8Cisco Ons 15454 System Software Ons 15454Ons 15454 Mspp+5 moreApr 29, 2026 Dec 18, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of serv...Show more |
1Cooperindustries 3Smp 16 Gateway (data Concentrator) Smp 4/dp Gateway (data Concentrator)Smp 4 Gateway (data Concentrator)Apr 29, 2026 Dec 17, 2013 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line. |