CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\\\\\localhost and http://localhost are the same U...Show more |
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. No...Show more |
IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially crafted JSON message, an attacker could...Show more |
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system. |
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution. |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not h...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to cra...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endp...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected e...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validati...Show more |
2Debian Openexr2Debian Linux OpenexrJun 17, 2026 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest...Show more |
2Apache Netapp2Active Iq Unified Manager PoiJun 17, 2026 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an ap...Show more |
URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9...Show more |
A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing t...Show more |
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system...Show more |
2Debian Image Processing Project2Debian Linux Image ProcessingJun 17, 2026 Mar 1, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from un...Show more |
An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically c...Show more |
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hell...Show more |
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 con...Show more |