← Back
CWE-20

12,723 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,723)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Minddezign
1Photo Gallery
Apr 23, 2026
May 4, 2009
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.
1Symantec
3Antivirus
Client SecurityEndpoint Protection
Apr 23, 2026
Apr 30, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager...Show more
Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager (SEPM) component in Symantec Endpoint Protection (SEP) before 11.0 MR2, allows remote attackers to inject arbitrary text into the login screen, and possibly conduct phishing attacks, via vectors involving a URL that is not properly handled.Show less
1Mcafee
13Active Virus Defense
Active VirusscanEmail Gateway+10 more
Apr 23, 2026
Apr 30, 2009
N/A· v4
N/A· v3
7.6 HIGH· v2
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Vi...Show more
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.Show less
1Peterselie
1Yourplace
Apr 23, 2026
Apr 29, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a ne...Show more
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a new account with the username of a target user.Show less
1Elkagroup
1Image Gallery
Apr 23, 2026
Apr 27, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a di...Show more
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.Show less
1Freebsd
1Freebsd
Apr 23, 2026
Apr 27, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading...Show more
The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.Show less
1Freedesktop
1Dbus
Apr 23, 2026
Apr 27, 2009
N/A· v4
N/A· v3
3.6 LOW· v2
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafte...Show more
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.Show less
1Apple
1Cups
Apr 23, 2026
Apr 24, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
1Revou
1Revou
Apr 23, 2026
Apr 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator's password...Show more
adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator's password and gain privileges via a direct request with modified newpass1 and newpass2 parameters in a Change operation.Show less
1Revou
1Tclone
Apr 23, 2026
Apr 24, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then a...Show more
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo.Show less
1China On Site
1Flexphpdirectory
Apr 23, 2026
Apr 24, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to th...Show more
Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/.Show less
1Sun
1Java System Delegated Administrator
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAG...Show more
CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter.Show less
4Apple
FoolabsGlyphandcog+1 more
4Cups
PopplerXpdf+1 more
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF fil...Show more
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.Show less
1Blogphp
1Blogphp
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action.
1Clamav
1Clamav
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
1Mozilo
1Mozilocms
Apr 23, 2026
Apr 22, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals t...Show more
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an error message.Show less
1Gscripts
1Dns Tools
Apr 23, 2026
Apr 22, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the provenance of this information is unknown; the details are obtained solely...Show more
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 23, 2026
Apr 22, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions...Show more
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Apr 22, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores the maximum NFS filename length, which allows local users to cause a denial of service (OOPS) via a lo...Show more
fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores the maximum NFS filename length, which allows local users to cause a denial of service (OOPS) via a long filename, related to the encode_lookup function.Show less
1Gofoxy
1Foxy
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value.