← Back
CWE-20

12,710 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,710)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Funkwerk
1System Software
Apr 23, 2026
Jan 17, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests.
1Menalto
1Gallery
Apr 23, 2026
Jan 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module.
1Videolan
1Vlc
Apr 23, 2026
Jan 17, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer dereference.
1Apple
1Safari
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.
1Tibco
3Enterprise Message Service
RtworksSmartsockets Rtserver
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted re...Show more
Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow.Show less
1Tibco
3Enterprise Message Service
RtworksSmartsockets Rtserver
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that...Show more
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.Show less
1Drupal
1Fileshare Module
Apr 23, 2026
Jan 15, 2008
N/A· v4
N/A· v3
8.5 HIGH· v2
Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.
1Drupal
1Meta Tags Module
Apr 23, 2026
Jan 15, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involvin...Show more
Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involving creation of a node.Show less
1Minimal Design
1Minimal Gallery
Apr 23, 2026
Jan 15, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.
1Photopost
1Photopost Vbgallery
Apr 23, 2026
Jan 12, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.
1Sap
1Maxdb
Apr 23, 2026
Jan 12, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes c...Show more
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Jan 11, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a...Show more
Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.Show less
1Microsoft
1Rich Textbox Control
Apr 23, 2026
Jan 11, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.
1Snitz Communications
1Snitz Forums 2000
Apr 23, 2026
Jan 10, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter.
1Pro Search
1Pro Search
Apr 23, 2026
Jan 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PRO-Search 0.17 and earlier allows remote attackers to cause a denial of service via certain values of the show_page and time parameters to the default URI.
1Sun
1Jre
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer derefere...Show more
Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.Show less
1Novell
1Netware Client
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER bu...Show more
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.Show less
1White Dune
1White Dune
Apr 23, 2026
Jan 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a .WRL file.
1Georgia Softworks
1Ssh2 Server
Apr 23, 2026
Jan 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as d...Show more
Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.Show less
1Clam Anti Virus
1Clamav
Apr 23, 2026
Dec 31, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.