← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Condor Project
Redhat
2Condor
Enterprise Mrg
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of servic...Show more
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.Show less
1Cisco
3Unified Ip Phone 9951
Unified Ip Phone 9971Unified Ip Phones 9900 Series Firmware
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.
1Cisco
3Unified Ip Phone 9951
Unified Ip Phone 9971Unified Ip Phones 9900 Series Firmware
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug ID CSCuh10343.
1Cisco
2Ios
Ios Xe
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
5.7 MEDIUM· v2
The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA type 11 packet, aka Bug ID CSCui21030.
1Cisco
2Unified Ip Phone 9951
Unified Ip Phone 9971
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.
1Cisco
1Identity Services Engine Software
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified oth...Show more
The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCui82666.Show less
1Menalto
1Gallery
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.
1Gnome
1Librsvg
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) is...Show more
GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Joomla
1Joomla
Apr 29, 2026
Oct 9, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions a...Show more
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Oct 9, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a differe...Show more
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3873, CVE-2013-3882, and CVE-2013-3885.Show less
1Microsoft
1.net Framework
Apr 29, 2026
Oct 9, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerabi...Show more
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerability."Show less
1Microsoft
1.net Framework
Apr 29, 2026
Oct 9, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or ha...Show more
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML document, aka "Entity Expansion Vulnerability."Show less
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
The CLI parser in Cisco NX-OS allows local users to bypass intended access restrictions, and overwrite or create arbitrary files, via shell output redirection, aka Bug IDs CSCts56672 and CSCts56669.
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13055.
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RIP service engine in Cisco NX-OS allows remote attackers to cause a denial of service (engine restart) via a malformed (1) RIPv4 or (2) RIPv6 message, aka Bug ID CSCtj73415.
1Citrix
2Netscaler Application Delivery Controller
Netscaler Application Delivery Controller Firmware
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Citrix NetScaler Application Delivery Controller (ADC) 10.0 before 10.0-76.7 allows remote attackers to cause a denial of service (nsconfigd crash and appliance reboot) via a crafted request.
1Gnu
2Eglibc
Glibc
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-de...Show more
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.Show less
1Ibm
1Infosphere Information Server
Apr 29, 2026
Oct 2, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface.
1Cisco
1Unified Computing System
Apr 29, 2026
Oct 2, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The create certreq command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86563.
1Cisco
1Unified Computing System
Apr 29, 2026
Oct 2, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
run-script in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86560.