← Back
CWE-20

12,713 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,713)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synactis
1All In The Box.ocx
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0'...Show more
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0' character, which bypasses the intended .box filename extension, as demonstrated by a C:\boot.ini\0 argument.Show less
1Squid
1Squid
Apr 23, 2026
Feb 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpM...Show more
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.Show less
1Hp
1Openview Network Node Manager
Apr 23, 2026
Feb 8, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via shell metacharacters in argument fields to the (1) webappmon.exe or (2) OpenView5.exe CGI program. NOT...Show more
HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via shell metacharacters in argument fields to the (1) webappmon.exe or (2) OpenView5.exe CGI program. NOTE: this issue may be partially covered by CVE-2009-0205.Show less
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path c...Show more
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.Show less
2Goahead
Goahead Software
2Goahead Webserver
Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data.
1.matteoiammarrone
1Iamma Simple Gallery
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it v...Show more
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.Show less
1Cisco
54400 Wireless Lan Controller
Catalyst 3750 Series Integrated Wireless Lan ControllerCatalyst 6500 Series Integrated Wireless Lan Controller+2 more
Apr 23, 2026
Feb 5, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller w...Show more
Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.1 allows remote attackers to cause a denial of service (device crash or hang) via unknown IP packets.Show less
1Cisco
54400 Wireless Lan Controller
Catalyst 3750 Series Integrated Wireless Lan ControllerCatalyst 6500 Series Integrated Wireless Lan Controller+2 more
Apr 23, 2026
Feb 5, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow...Show more
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.Show less
1Cisco
54400 Wireless Lan Controller
Catalyst 3750 Series Integrated Wireless Lan ControllerCatalyst 6500 Series Integrated Wireless Lan Controller+2 more
Apr 23, 2026
Feb 5, 2009
N/A· v4
N/A· v3
6.1 MEDIUM· v2
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote...Show more
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service (web authentication outage or device reload) via unspecified network traffic, as demonstrated by a vulnerability scanner.Show less
1Syslserve
1Syslserve
Apr 23, 2026
Feb 5, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Syslserve 1.058 and earlier, and probably 1.059, allows remote attackers to cause a denial of service (hang) via a crafted UDP Syslog packet.
1Hp
1Hp Ux
Apr 23, 2026
Feb 4, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service...Show more
The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity), read private network traffic, and possibly execute arbitrary code via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.Show less
1Sony Ericsson
9K530i
K610iK618i+6 more
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packet to (1) SMS or (2)...Show more
The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packet to (1) SMS or (2) UDP port 2948.Show less
1Memht
1Memht Portal
Apr 23, 2026
Jan 30, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an...Show more
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.Show less
1Emc
1Autostart
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.
1Windows Tftp Utility
1Tftputil
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request.
1Globsy
1Globsy
Apr 23, 2026
Jan 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter.
1Sun
2Opensolaris
Solaris
Apr 23, 2026
Jan 26, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a differen...Show more
libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.Show less
1Gravity Gtd
1Gravity Gtd
Apr 23, 2026
Jan 23, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitrary PHP code via the objectname parameter.