← Back
CWE-20

12,745 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,745)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Certificate System
Apr 29, 2026
Jan 4, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty s...Show more
The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.Show less
2Debian
Drupal
2Debian Linux
Drupal
Apr 29, 2026
Jan 3, 2013
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
1Opera
1Opera Browser
Apr 29, 2026
Jan 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indication of successful revocation-status checking by causing a failure of a si...Show more
The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indication of successful revocation-status checking by causing a failure of a single checking service.Show less
1Vbulletin
1Vbulletin
Apr 29, 2026
Dec 31, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter in a lostpw action.
1Cisco
3Skinny Client Control Protocol Software
Unified Ip PhoneUnified Ip Phone 7906g
Apr 29, 2026
Dec 28, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute...Show more
The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.Show less
1Ibm
2Rational Policy Tester
Security Appscan
Apr 29, 2026
Dec 28, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoo...Show more
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.Show less
1Ibm
2Rational Policy Tester
Security Appscan
Apr 29, 2026
Dec 28, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary...Show more
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Dec 27, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via...Show more
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.Show less
1Squid Cache
1Squid
Apr 29, 2026
Dec 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1)...Show more
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.Show less
1Huawei
2E585
E585u 82
Apr 29, 2026
Dec 19, 2012
N/A· v4
N/A· v3
4.8 MEDIUM· v2
The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network.
1Symantec
1Endpoint Protection
Apr 29, 2026
Dec 18, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP...Show more
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.Show less
1Owncloud
2Owncloud
Owncloud Server
Apr 29, 2026
Dec 18, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a special crafted name.
1Xen
1Xen
Apr 29, 2026
Dec 13, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecifie...Show more
The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.Show less
1Microsoft
2Windows Server 2008
Windows Server 2012
Apr 29, 2026
Dec 12, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The IP-HTTPS server in Windows Server 2008 R2 and R2 SP1 and Server 2012 does not properly validate certificates, which allows remote attackers to bypass intended access restrictions via a revoked certificate, aka "Revok...Show more
The IP-HTTPS server in Windows Server 2008 R2 and R2 SP1 and Server 2012 does not properly validate certificates, which allows remote attackers to bypass intended access restrictions via a revoked certificate, aka "Revoked Certificate Bypass Vulnerability."Show less
1Google
1Android
Apr 29, 2026
Dec 10, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SRC attribute of an IFRAME element.
2Canonical
Isc
2Bind
Ubuntu Linux
Apr 29, 2026
Dec 6, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
1Wireshark
1Wireshark
Apr 29, 2026
Dec 5, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a craf...Show more
The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.Show less
1Wireshark
1Wireshark
Apr 29, 2026
Dec 5, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dissect_isakmp function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses an incorrect data structure to determine IKEv2 decryption parameters, wh...Show more
The dissect_isakmp function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses an incorrect data structure to determine IKEv2 decryption parameters, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.Show less
1Forescout
1Counteract
Apr 29, 2026
Dec 5, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.
1Emc
1Rsa Netwitness Informer
Apr 29, 2026
Dec 5, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to conduct clickjacking attacks via unspecified vectors.