CWE-20
12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,815)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Webex Meetings Server Webex Node For McsApr 29, 2026 May 3, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka Bug IDs CSCue36664 and CSCue36629. |
EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attack...Show more |
The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a READDIR request is for a directory node, which allows remote attackers to...Show more |
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to a...Show more |
1Cisco 1Telepresence Management Suite Apr 29, 2026 May 1, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 TMSSNMPService.exe in TelePresence Manager in Cisco TelePresence Management Suite (TMS) on 64-bit platforms allows remote attackers to cause a denial of service (process crash) via SNMP traps, aka Bug ID CSCue00028. |
The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeated requests." |
1Cisco 11Application Networking Manager Context Directory AgentIdentity Services Engine Software+8 moreApr 29, 2026 Apr 29, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management...Show more |
2Erik Michaels Ober Grape Project2Grape Multi XmlApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute ar...Show more |
1Cisco 10Adaptive Security Appliance Device Manager Mds 9000Nexus 5000+7 moreApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 The JAR files on Cisco Device Manager for Cisco MDS 9000 devices before 5.2.8, and Cisco Device Manager for Cisco Nexus 5000 devices, allow remote attackers to execute arbitrary commands on Windows client machines via a...Show more |
1Cisco 6Unified Computing System 6120xp Fabric Interconnect Unified Computing System 6140xp Fabric InterconnectUnified Computing System 6248up Fabric Interconnect+3 moreApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The management API in the XML API management service in the Manager component in Cisco Unified Computing System (UCS) 1.x before 1.2(1b) allows remote attackers to cause a denial of service (service outage) via a malform...Show more |
1Cisco 12Nexus 3016q Nexus 3048Nexus 3064t+9 moreApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N2(2), Nexus 3000 devices 5.x before 5.0(3)U3(2), and Unified Computing System (UCS) 6200 devices before 2.0(1w) allows remote attackers to cause a denial of ser...Show more |
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, whi...Show more |
The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app....Show more |
1Cisco 12Telepresence Mcu 4500 Series Software Telepresence Mcu 4501Telepresence Mcu 4501 Series Software+9 moreApr 29, 2026 Apr 18, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence Server before 2.3(1.55) does not properly validate H.264 data, which all...Show more |
1Rockwellautomation 1Rslinx Enterprise Apr 29, 2026 Apr 18, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage) via a zero-b...Show more |
The XML parser in the server in Cisco Unified Presence (CUP) allows remote authenticated users to cause a denial of service (jabberd daemon crash) via crafted XML content in an XMPP message, aka Bug ID CSCue13912. |
1Cisco 1Jabber Extensible Communications Platform Apr 29, 2026 Apr 16, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Connection Manager in Cisco Jabber Extensible Communications Platform (aka Jabber XCP) does not properly validate login data, which allows remote attackers to cause a denial of service (service crash) by sending a se...Show more |
1Cisco 9Asr 1001 Asr 1002Asr 1002 X+6 moreApr 29, 2026 Apr 11, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows r...Show more |
Cisco Universal Broadband (aka uBR) 10000 series routers, when an IPv4/IPv6 dual-stack modem is used, allow remote attackers to cause a denial of service (routing-engine reload) via unspecified changes to IP address assi...Show more |
1Cisco 1Anyconnect Secure Mobility Client Apr 29, 2026 Apr 11, 2013 N/A· v4 N/A· v3 6.6 MEDIUM· v2 The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153...Show more |