← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Ios
Ios Xe
Apr 29, 2026
Sep 27, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (...Show more
Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.Show less
1Cisco
2Ios
Ios Xe
Apr 29, 2026
Sep 27, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attack...Show more
The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.Show less
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 26, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify a...Show more
The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing an identity, aka Bug ID CSCtk00683.Show less
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 26, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The XML API service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service (API service outage) via a malformed XML document in a packet, aka Bug...Show more
The XML API service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service (API service outage) via a malformed XML document in a packet, aka Bug ID CSCtg48206.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Sep 25, 2013
N/A· v4
N/A· v3
3.8 LOW· v2
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem wr...Show more
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.Show less
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 24, 2013
N/A· v4
N/A· v3
6.6 MEDIUM· v2
MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-lev...Show more
MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.Show less
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 24, 2013
N/A· v4
N/A· v3
5.1 MEDIUM· v2
A cluster setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20793.
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 24, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Intelligent Platform Management Interface (IPMI) implementation in the Blade Management Controller in Cisco Unified Computing System (UCS) allows remote attackers to enumerate valid usernames by observing IPMI interf...Show more
The Intelligent Platform Management Interface (IPMI) implementation in the Blade Management Controller in Cisco Unified Computing System (UCS) allows remote attackers to enumerate valid usernames by observing IPMI interface responses, aka Bug ID CSCtg20761.Show less
1Simon Mcvittie
1Telepathy Gabble
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to b...Show more
The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.Show less
1Jforum
1Jforum
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin action to jforum.page.
1Ibm
2Websphere Application Server
Websphere Application Server Feature Pack For Web Services
Apr 29, 2026
Sep 20, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, wh...Show more
The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors.Show less
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 20, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
MCTools in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to gain privileges by entering crafted command-line parameters on a Fabric Interconnect device, aka Bug ID CSCtg20749.
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 20, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Manager component in Cisco Unified Computing System (UCS) allows local users to cause a denial of service via an invalid Smart Call Home contact address, aka Bug ID CSCtl00186.
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 20, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledg...Show more
The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key, aka Bug ID CSCte90327.Show less
1Apple
1Iphone Os
Apr 29, 2026
Sep 19, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite loop) via an application that writes crafted values to /dev/random.
1Apple
1Iphone Os
Apr 29, 2026
Sep 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
1Apple
1Iphone Os
Apr 29, 2026
Sep 19, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion failure and device restart) via an invalid packet fragment.
1Apple
3Iphone Os
ItunesMac Os X
Apr 29, 2026
Sep 19, 2013
N/A· v4
N/A· v3
6.1 MEDIUM· v2
The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets.
1Mozilla
4Firefox
SeamonkeyThunderbird+1 more
Apr 29, 2026
Sep 18, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey b...Show more
Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via vectors related to image-document scrolling.Show less
1Mozilla
1Firefox
Apr 29, 2026
Sep 18, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in the GL tracing functionality in Mozilla Firefox before 24.0 on Android allows attackers to execute arbitrary code via a Trojan horse .so file in a world-writable directory.