← Back
CWE-20

12,710 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,710)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ssl Explorer
1Ssl Explorer
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in selectLanguage.do in SSL-Explorer before 0.2.15 allows remote attackers to inject (1) headers or (2) body data in an HTTP transaction, a different vulnerability than CVE-2007-2907. NOTE: some...Show more
Unspecified vulnerability in selectLanguage.do in SSL-Explorer before 0.2.15 allows remote attackers to inject (1) headers or (2) body data in an HTTP transaction, a different vulnerability than CVE-2007-2907. NOTE: some of these details are obtained from third party information.Show less
1Avaya
2Message Networking
Messaging Storage Server
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, allows remote attackers to cause a denial of service via unspecified vect...Show more
Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, allows remote attackers to cause a denial of service via unspecified vectors related to "input validation."Show less
1Firefly
1Media Server
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.1 HIGH· v2
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authoriza...Show more
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line without a ':' character, which triggers a crash in the ws_getheaders function.Show less
1Hitachi
14Cosminexus Application Server Enterprise
Cosminexus Application Server StandardCosminexus Developer Light Version 6+11 more
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate w...Show more
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.Show less
1Ghlab
1Korean Ghboard
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restrictions and upload arbitrary files via a...Show more
The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restrictions and upload arbitrary files via a modified copy of component/flashupload/upload.html.Show less
1Ghlab
1Korean Ghboard
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in component/upload.jsp in Korean GHBoard allows remote attackers to upload arbitrary files via unspecified vectors, probably involving a direct request.
1Seeblick
1Seeblick
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unrestricted file upload vulnerability in upload.php in SeeBlick 1.0 Beta allows remote attackers to upload arbitrary files via unspecified vectors. NOTE: these files are stored with .html extensions, so the scope of th...Show more
Unrestricted file upload vulnerability in upload.php in SeeBlick 1.0 Beta allows remote attackers to upload arbitrary files via unspecified vectors. NOTE: these files are stored with .html extensions, so the scope of the attack might be limited to resource consumption and possibly XSS.Show less
1Efileman
1Efileman
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unrestricted file upload vulnerability in eFileMan 7.1.0.87-88 allows remote attackers to upload arbitrary files, with "uploads/upload_file." destination filenames, via unspecified vectors to upload.cgi, accessed from up...Show more
Unrestricted file upload vulnerability in eFileMan 7.1.0.87-88 allows remote attackers to upload arbitrary files, with "uploads/upload_file." destination filenames, via unspecified vectors to upload.cgi, accessed from upload.html.Show less
1Japanese Php Gallery Hosting
1Japanese Php Gallery Hosting
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in upload/upload.php in Japanese PHP Gallery Hosting, when Open directory mode is enabled, allows remote attackers to upload and execute arbitrary PHP code via a ServerPath paramete...Show more
Unrestricted file upload vulnerability in upload/upload.php in Japanese PHP Gallery Hosting, when Open directory mode is enabled, allows remote attackers to upload and execute arbitrary PHP code via a ServerPath parameter specifying a filename with a double extension. NOTE: some of these details are obtained from third party information.Show less
1Massive Entertainment
1World In Conflict
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Massive Entertainment World in Conflict 1.001 and earlier allows remote attackers to cause a denial of service (failed assertion and daemon crash) via a large packet to TCP or UDP port 48000.
1Pidgin
1Pidgin
Apr 23, 2026
Oct 29, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different v...Show more
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.Show less
1Mozilla
1Firefox
Apr 23, 2026
Oct 29, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service (application crash) via a crafted reply to an unspecified listing command, related to "reading from invalid pointer."
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 23, 2026
Oct 21, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML tha...Show more
Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 23, 2026
Oct 21, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corrupt...Show more
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.Show less
1Cisco
1Firewall Services Module
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS request, aka CSCsi77844.
1Cisco
3Adaptive Security Appliance
Adaptive Security Appliance SoftwarePix 500
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the device, allow remote attackers to cause a denial of service (device reload) via a crafted TLS packet, aka CSCsg43276 and CSC...Show more
Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the device, allow remote attackers to cause a denial of service (device reload) via a crafted TLS packet, aka CSCsg43276 and CSCsh97120.Show less
1Cisco
2Adaptive Security Appliance Software
Firewall Services Module
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka...Show more
Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM).Show less
1Virtuemart
1Virtuemart
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in VirtueMart before 1.0.13 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
1Nec
1Mobile Handset
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the NEC mobile handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable...Show more
Unspecified vulnerability in the NEC mobile handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less
1Avaya
1Voip Handset
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable...Show more
Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less