← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Selinc
4Sel 2241
Sel 3505Sel 3530+1 more
Apr 29, 2026
Aug 9, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
Schweitzer Engineering Laboratories (SEL) SEL-2241, SEL-3505, and SEL-3530 RTAC master devices allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.
1Mozilla
4Firefox
SeamonkeyThunderbird+1 more
Apr 29, 2026
Aug 7, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to...Show more
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message Format (CRMF) request generation.Show less
1Ibm
1Infosphere Biginsights
Apr 29, 2026
Aug 6, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
IBM InfoSphere BigInsights 1.1 through 2.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.
1Python
1Setuptools
Apr 29, 2026
Aug 6, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code...Show more
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.Show less
1Guillaume Gauvrit
1Pyshop
Apr 29, 2026
Aug 6, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted res...Show more
pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.Show less
1Pypa
1Pip
Apr 29, 2026
Aug 6, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response...Show more
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.Show less
1Monkey Project
1Monkey
Apr 29, 2026
Aug 1, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.
1Cisco
1Wide Area Application Services
Apr 29, 2026
Aug 1, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a craf...Show more
The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.Show less
1Siemens
1Wincc
Apr 29, 2026
Aug 1, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMA...Show more
Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.Show less
1Ibm
1Websphere Commerce
Apr 29, 2026
Aug 1, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of...Show more
IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.Show less
1Symantec
3Web Gateway
Web Gateway Appliance 8450Web Gateway Appliance 8490
Apr 29, 2026
Aug 1, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login...Show more
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.Show less
3Apache
CollabnetOpensuse
3Opensuse
SubversionSubversion
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
1Wireshark
1Wireshark
Apr 29, 2026
Jul 30, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allow remote attackers to cause a denial of service (application...Show more
Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allow remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
1Wireshark
1Wireshark
Apr 29, 2026
Jul 30, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dissect_dvbci_tpdu_hdr function in epan/dissectors/packet-dvbci.c in the DVB-CI dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not validate a certain length value before decrementing it, whic...Show more
The dissect_dvbci_tpdu_hdr function in epan/dissectors/packet-dvbci.c in the DVB-CI dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not validate a certain length value before decrementing it, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet.Show less
1Wireshark
1Wireshark
Apr 29, 2026
Jul 30, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine whether there is remaining packet data to process, which allows remote attackers t...Show more
epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine whether there is remaining packet data to process, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
1Wireshark
1Wireshark
Apr 29, 2026
Jul 30, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly validate certain index values, which allows remote attackers to cause a denial of service (a...Show more
epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly validate certain index values, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The bridge multicast implementation in the Linux kernel through 3.10.3 does not check whether a certain timer is armed before modifying the timeout value of that timer, which allows local users to cause a denial of servi...Show more
The bridge multicast implementation in the Linux kernel through 3.10.3 does not check whether a certain timer is armed before modifying the timeout value of that timer, which allows local users to cause a denial of service (BUG and system crash) via vectors involving the shutdown of a KVM virtual machine, related to net/bridge/br_mdb.c and net/bridge/br_multicast.c.Show less
1Trustgo
1Antivirus & Mobile Security
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The TrustGo Antivirus & Mobile Security application before 1.3.6 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.trustgo.mobile.security...Show more
The TrustGo Antivirus & Mobile Security application before 1.3.6 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.trustgo.mobile.security.USSDScannerActivity with zero arguments.Show less
1Apache
1Struts
Apr 29, 2026
Jul 20, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: o...Show more
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.Show less
1Emc
2Avamar Server
Avamar Server Virtual Edition
Apr 29, 2026
Jul 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive informa...Show more
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive information via a crafted web site, related to "cross frame scripting vulnerabilities."Show less