← Back
CWE-20

13,120 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (13,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kaspersky Lab
1Kaspersky Anti Virus
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.
1Posadis
1Posadis
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.
1Burton Computer Corporation
1Spamprobe
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.
1Cpanel
1Cpanel
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
1Netscape
1Navigator
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
1Bisonftp
1Bisonftp Server 4
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.
1Dotbr
1Botbr
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.
1Dotbr
1Botbr
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
1Kietu
1Kietu
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.
1Perl
1Cgi Lite
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return,...Show more
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.Show less
1Aprelium Technologies
1Abyss Web Server
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
8.5 HIGH· v2
Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.
1List Site Pro
1List Site Pro
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.
1Monkey Project
1Monkey
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.
3Gnu
QuaggaSgi
3Propack
QuaggaZebra
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) v...Show more
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.Show less
1Cisco
3Ios
Ons 15454 Optical Transport PlatformOptical Networking Systems Software
Apr 16, 2026
Aug 18, 2003
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that in...Show more
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.Show less
2Debian
Gnu
2Debian Linux
Gzip
Apr 16, 2026
Jul 2, 2003
N/A· v4
N/A· v3
2.1 LOW· v2
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
1Sendmail
1Sendmail
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.
1Andrey Cherezov
1Acweb
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.8 HIGH· v2
acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.
1Independent Solution
2Simple Site Searcher
Super Site Searcher
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
1Alliedtelesyn
2At 8024
Rapier 24
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.