CWE-20
12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,815)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCub23...Show more |
1Ibm 1Rational Requirements Composer Apr 29, 2026 Sep 12, 2013 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. |
1Microsoft 6Active Directory Lightweight Directory Service Windows 7Windows 8+3 moreApr 29, 2026 Sep 11, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Active Directory Lightweight Directory Service (AD LDS) on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 and Active Directory Services on Windows Server 2008 SP2 and R2 SP1...Show more |
Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arbitrary files via an XML document containing an external entity declara...Show more |
1Microsoft 5Office Web Apps Sharepoint FoundationSharepoint Portal Server+2 moreApr 29, 2026 Sep 11, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 does not set the EnableViewStateMac attribute, which allows remote attac...Show more |
1Microsoft 4Sharepoint Foundation Sharepoint Portal ServerSharepoint Server+1 moreApr 29, 2026 Sep 11, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP proces...Show more |
1Fedoraproject 1389 Directory Server Apr 29, 2026 Sep 10, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request. |
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file. |
1Digium 3Asterisk Asterisk DigiumphonesCertified AsteriskApr 29, 2026 Sep 9, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2; and Aster...Show more |
The Search component in IBM WebSphere Commerce 7.0 FP4 through FP6, in certain search-term association configurations, allows remote attackers to cause a denial of service via a crafted query. |
1Supermicro 126H8dcl 6f H8dcl IfH8dct Hibqf+123 moreApr 29, 2026 Sep 8, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, a...Show more |
1Supermicro 126H8dcl 6f H8dcl IfH8dct Hibqf+123 moreApr 29, 2026 Sep 8, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, a...Show more |
1Trivantis 1Coursemill Learning Management System Apr 29, 2026 Sep 6, 2013 N/A· v4 N/A· v3 8.5 HIGH· v2 Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to gain privileges via a modified userid value to unspecified functions. |
1Trivantis 1Coursemill Learning Management System Apr 29, 2026 Sep 6, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html. |
Open redirect vulnerability in EMC RSA Archer GRC 5.x before 5.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. |
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger...Show more |
Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows remote attackers to cause a denial of service (process crash) via malformed TCP packets, aka Bug ID...Show more |
VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled exception and applicati...Show more |
Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref I...Show more |
The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731. |