← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cooperindustries
1Dnp3 Master Opc Server
Apr 29, 2026
Dec 17, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
Cooper Power Systems Cybectec DNP3 Master OPC Server allows remote attackers to cause a denial of service (unhandled exception and process crash) via unspecified vectors.
1Cooperindustries
3Smp 16 Gateway (data Concentrator)
Smp 4/dp Gateway (data Concentrator)Smp 4 Gateway (data Concentrator)
Apr 29, 2026
Dec 17, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows remote attackers to cause a denial of service (reboot or link outage) via a crafted DNP3 TCP packet.
1Cisco
1Webex Training Center
Apr 29, 2026
Dec 17, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36031.
1Cisco
1Webex Training Center
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul57140.
1Cisco
1Webex Training Center
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.
1Cisco
1Webex Sales Center
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CS...Show more
Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36020.Show less
1Cisco
1Webex Sales Center
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul25557.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.
2Linux
Opensuse
2Linux Kernel
Opensuse
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
1Devscripts Devel Team
1Devscripts
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.
1Munin Monitoring
1Munin
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.
1Munin Monitoring
1Munin
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigrap...Show more
The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Dec 11, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer...Show more
Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Dec 11, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer El...Show more
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."Show less
1Microsoft
4Windows 8
Windows RtWindows Rt 8.1+1 more
Apr 29, 2026
Dec 11, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueT...Show more
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."Show less
1Microsoft
2Windows Server 2003
Windows Xp
Apr 29, 2026
Dec 11, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memor...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."Show less
1Linux
1Linux Kernel
Apr 29, 2026
Dec 9, 2013
N/A· v4
N/A· v3
3.6 LOW· v2
The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted...Show more
The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Dec 9, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly h...Show more
The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data.Show less
1Ffmpeg
1Ffmpeg
Apr 29, 2026
Dec 9, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or...Show more
The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Flash Screen Video data.Show less
1Nowsms
1Now Sms & Mms Gateway
Apr 29, 2026
Dec 7, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Multimedia Messaging Centre (MMSC) in NowSMS Now SMS & MMS Gateway before 2013.11.15 allows remote attackers to cause a denial of service via a malformed MM1 message that is routed to a (1) MM4 or (2) MM7 connection.