← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bisonftp
1Bisonftp Server 4
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.
1Dotbr
1Botbr
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.
1Dotbr
1Botbr
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
1Kietu
1Kietu
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.
1Perl
1Cgi Lite
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return,...Show more
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.Show less
1Aprelium Technologies
1Abyss Web Server
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
8.5 HIGH· v2
Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.
1List Site Pro
1List Site Pro
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.
1Monkey Project
1Monkey
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.
3Gnu
QuaggaSgi
3Propack
QuaggaZebra
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) v...Show more
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.Show less
1Cisco
3Ios
Ons 15454 Optical Transport PlatformOptical Networking Systems Software
Apr 16, 2026
Aug 18, 2003
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that in...Show more
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.Show less
2Debian
Gnu
2Debian Linux
Gzip
Apr 16, 2026
Jul 2, 2003
N/A· v4
N/A· v3
2.1 LOW· v2
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
1Sendmail
1Sendmail
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.
1Andrey Cherezov
1Acweb
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.8 HIGH· v2
acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.
1Independent Solution
2Simple Site Searcher
Super Site Searcher
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
1Alliedtelesyn
2At 8024
Rapier 24
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.
1Perception
1Liteserve
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.
1Solarwinds
1Serv U File Server
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD comma...Show more
Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.Show less
1Linksys
1Wet11
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.8 HIGH· v2
Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.
1Springer Verlag Berlin Heidelberg
1Simple Wais
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.
1Netgear
1Fm114p
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.8 HIGH· v2
Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests.