← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Barebones
3Bbedit
TextwranglerYojimbo
Apr 29, 2026
Dec 31, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attacke...Show more
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.Show less
1Hot
2Hotbox Router
Hotbox Router Firmware
Apr 29, 2026
Dec 30, 2013
N/A· v4
N/A· v3
6.1 MEDIUM· v2
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.
1Microsoft
1Windows Movie Maker
Apr 29, 2026
Dec 30, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.
1Cisco
1Ios Xe
Apr 29, 2026
Dec 28, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.
1Optimizepress
1Optimizepress
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/admin/ in the OptimizePress theme before 1.61 for WordPress allow remote...Show more
Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/admin/ in the OptimizePress theme before 1.61 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images_comingsoon, images_lncthumbs, or images_optbuttons in wp-content/uploads/optpress/, as exploited in the wild in November 2013.Show less
1Typo3
1Typo3
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and...Show more
Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.Show less
3Canonical
DebianHaxx
3Debian Linux
LibcurlUbuntu Linux
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it e...Show more
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.Show less
2Digia
Qt
2Qt
Qt
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack.
1Idleman
1Leed
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.
1Novell
1Client
Apr 29, 2026
Dec 22, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL.
1Ibm
2Sterling B2b Integrator
Sterling File Gateway
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors.
1Ibm
2Sterling B2b Integrator
Sterling File Gateway
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information...Show more
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.Show less
1Ibm
1Spss Collaboration And Deployment Services
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via...Show more
Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.Show less
1Novatech
6Orion5 Dnp Master
Orion5 Dnp SlaveOrion5r Dnp Master+3 more
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to c...Show more
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to cause a denial of service (driver crash and process restart) via crafted input over a serial line.Show less
1Novatech
6Orion5 Dnp Master
Orion5 Dnp SlaveOrion5r Dnp Master+3 more
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial...Show more
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial of service (driver crash and process restart) via a crafted DNP3 TCP packet.Show less
1Wireshark
1Wireshark
Apr 29, 2026
Dec 19, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafte...Show more
epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
1Wireshark
1Wireshark
Apr 29, 2026
Dec 19, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a deni...Show more
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.Show less
1Ibm
1Content Navigator
Apr 29, 2026
Dec 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via v...Show more
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via vectors involving FRAME elements.Show less
1Cisco
8Cisco Ons 15454 System Software
Ons 15454Ons 15454 Mspp+5 more
Apr 29, 2026
Dec 18, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of serv...Show more
The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of service (watchdog timeout and TNC reset) via a flood of network traffic, aka Bug ID CSCud97155.Show less
1Cooperindustries
3Smp 16 Gateway (data Concentrator)
Smp 4/dp Gateway (data Concentrator)Smp 4 Gateway (data Concentrator)
Apr 29, 2026
Dec 17, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.