← Back
CWE-20

12,734 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,734)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Tivoli Federated Identity Manager
Apr 29, 2026
Aug 12, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.
1Hp
2Proliant Sl Advanced Power Manager
Proliant Sl Advanced Power Manager Firmware
Apr 29, 2026
Aug 11, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause a denial of service via unspecified vectors.
1Wordpress
1Wordpress
Apr 29, 2026
Aug 10, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacki...Show more
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.Show less
1Microsoft
1Visio
Apr 29, 2026
Aug 10, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vul...Show more
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."Show less
1Microsoft
1Visio
Apr 29, 2026
Aug 10, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream R...Show more
Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."Show less
1Microsoft
1Windows Server 2008
Apr 29, 2026
Aug 10, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, a...Show more
The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Aug 10, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers...Show more
Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers "inactive filtering," aka "Shift JIS Character Encoding Vulnerability."Show less
1Uusee
2Uuplayer Activex Control
Uusee
Apr 29, 2026
Aug 9, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The Play method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 allows remote attackers to execute arbitrary programs via a UNC share pathname in the MPlayerPath parameter.
4Ioquake3
TremulousUrbanterror+1 more
4Ioquake3 Engine
IourbanterrorTremulous+1 more
Apr 29, 2026
Aug 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote att...Show more
The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.Show less
1Mozilla
1Bugzilla
Apr 29, 2026
Aug 9, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 does not prevent changes to the confirmation e-mail address (aka old...Show more
Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 does not prevent changes to the confirmation e-mail address (aka old_email field) for e-mail change notifications, which makes it easier for remote attackers to perform arbitrary address changes by leveraging an unattended workstation.Show less
1Ruby Lang
1Ruby
Apr 29, 2026
Aug 5, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predic...Show more
The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.Show less
6Ioquake3
OpenarenaSmokin Guns+3 more
6Ioquake3 Engine
IourbanterrorOpenarena+3 more
Apr 29, 2026
Aug 4, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dang...Show more
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.Show less
3Ioquake3
OpenarenaWorldofpadman
3Ioquake3 Engine
OpenarenaWorld Of Padman
Apr 29, 2026
Aug 4, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharact...Show more
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.Show less
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a...Show more
Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.Show less
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact v...Show more
Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted web site.Show less
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the GPU lock, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio recordings via a crafted web page containing...Show more
Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio recordings via a crafted web page containing an INPUT element.Show less
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via...Show more
Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.Show less
3Apple
DebianGoogle
5Chrome
Debian LinuxIphone Os+2 more
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to...Show more
Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."Show less