← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Unified Ip Phone 8945
Unified Ip Phone Firmware
Apr 29, 2026
Aug 29, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270.
1Fail2ban
1Fail2ban
Apr 29, 2026
Aug 28, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote attackers to block arbitrary IP address...Show more
The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote attackers to block arbitrary IP addresses via certain messages in a request.Show less
2Openstack
Opensuse
2Opensuse
Python Glanceclient
Apr 29, 2026
Aug 28, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common N...Show more
The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less
1Softwaretoolbox
1Top Server
Apr 29, 2026
Aug 28, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The DNP Master Driver in Software Toolbox TOP Server before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically...Show more
The DNP Master Driver in Software Toolbox TOP Server before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input over a serial line.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Aug 25, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system cr...Show more
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.Show less
2Apache
Redhat
2Enterprise Mrg
Qpid
Apr 29, 2026
Aug 23, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middl...Show more
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less
1Ibm
2Global Console Manager 16 Firmware
Global Console Manager 32 Firmware
Apr 29, 2026
Aug 21, 2013
N/A· v4
N/A· v3
8.5 HIGH· v2
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacha...Show more
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.Show less
1Puppet
1Puppet Enterprise
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the service parameter.
1Puppet
1Puppet Enterprise
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote attackers to hijack sessions by obtaining an old session ID.
1Apache
1Xml Security For C++
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanis...Show more
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.Show less
2Opensuse
Phpmyadmin
2Opensuse
Phpmyadmin
Apr 29, 2026
Aug 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.
4Canonical
NovellPuppet+1 more
6Puppet
PuppetPuppet Enterprise+3 more
Apr 29, 2026
Aug 19, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a cra...Show more
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.Show less
3Canonical
OpensusePerlmonks
3Module\
OpensuseUbuntu Linux
Apr 29, 2026
Aug 19, 2013
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that r...Show more
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.Show less
4Canonical
DebianHaproxy+1 more
4Debian Linux
Enterprise Linux Load BalancerHaproxy+1 more
Apr 29, 2026
Aug 19, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index us...Show more
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.Show less
3Canonical
PhpRedhat
3Enterprise Linux
PhpUbuntu Linux
Apr 29, 2026
Aug 18, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509...Show more
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.Show less
3Canonical
OpensusePython
3Opensuse
PythonUbuntu Linux
Apr 29, 2026
Aug 18, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-th...Show more
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.Show less
1Apache
1Ofbiz
Apr 29, 2026
Aug 15, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharac...Show more
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.Show less
1Xen
1Xen
Apr 29, 2026
Aug 14, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
1Ioserver
1Ioserver
Apr 29, 2026
Aug 13, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000.
1Selinc
4Sel 2241
Sel 3505Sel 3530+1 more
Apr 29, 2026
Aug 9, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Schweitzer Engineering Laboratories (SEL) SEL-2241, SEL-3505, and SEL-3530 RTAC master devices allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.