← Back
CWE-20

12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,947)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Typo3
1Typo3
Jun 17, 2026
Oct 5, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that TYPO3 CMS is susceptible to host spoofing due to improper validation of the HTTP Host header. TYPO3...Show more
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that TYPO3 CMS is susceptible to host spoofing due to improper validation of the HTTP Host header. TYPO3 uses the HTTP Host header, for example, to generate absolute URLs during the frontend rendering process. Since the host header itself is provided by the client, it can be forged to any value, even in a name-based virtual hosts environment. This vulnerability is the same as described in TYPO3-CORE-SA-2014-001 (CVE-2014-3941). A regression, introduced during TYPO3 v11 development, led to this situation. The already existing setting $GLOBALS['TYPO3_CONF_VARS']['SYS']['trustedHostsPattern'] (used as an effective mitigation strategy in previous TYPO3 versions) was not evaluated anymore, and reintroduced the vulnerability.Show less
3Netapp
OraclePhp
3Clustered Data Ontap
PhpSd Wan Aware
Jun 17, 2026
Oct 4, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can b...Show more
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.Show less
1Atlassian
1Floodlight
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.
1Atlassian
1Floodlight
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.
1Adobe
1Creative Cloud Desktop Application
Jun 17, 2026
Sep 29, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a normal user to delete the OOBE directory and get permissions of any dire...Show more
Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a normal user to delete the OOBE directory and get permissions of any directory under the administrator authority.Show less
1Dell
85Chengming 3990 Firmware
Chengming 3991 FirmwareG3 15 3500 Firmware+82 more
Jun 17, 2026
Sep 28, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
1Adobe
1Experience Manager
Jun 17, 2026
Sep 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side d...Show more
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.Show less
1Zoom
4Meeting Connector
Recording ConnectorVirtual Room Connector+1 more
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Rec...Show more
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.Show less
1Zoom
4Meeting Connector
Recording ConnectorVirtual Room Connector+1 more
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Record...Show more
The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal administrator.Show less
1Phoenixcontact
6Axc F 1152 Firmware
Axc F 2152 FirmwareAxc F 2152 Starterkit Firmware+3 more
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.
1Eduvpn
1Vpn User Portal
Jun 17, 2026
Sep 24, 2021
N/A· v4
6.5 MEDIUM· v3
9.0 HIGH· v2
vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes wit...Show more
vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes with an exec that uses the -r option. This can be leveraged to obtain additional VPN access.Show less
1Cisco
6Firepower Extensible Operating System
FxosIos+3 more
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.4 HIGH· v3
5.7 MEDIUM· v2
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjac...Show more
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An attacker could exploit this vulnerability by sending specifically crafted UDLD packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerability are strict. An attacker must have full control of a directly connected device. On Cisco IOS XR devices, the impact is limited to the reload of the UDLD process.Show less
1Redhat
3Ansible Automation Platform
Ansible EngineAnsible Tower
Jun 17, 2026
Sep 22, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and th...Show more
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.Show less
1Butter Project
1Butter
Jun 17, 2026
Sep 21, 2021
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are recommend to update to the Trinity kernel. There are no workarounds.
1Nlnetlabs
1Routinator
Jun 17, 2026
Sep 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This will lead to RTR clients such as routers to reject the RPKI data set, effe...Show more
NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This will lead to RTR clients such as routers to reject the RPKI data set, effectively disabling Route Origin Validation.Show less
1Kubernetes
1Kubernetes
Jun 17, 2026
Sep 20, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
1Realvnc
1Vnc Viewer
Jun 17, 2026
Sep 17, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires social engineering a user into connecting to...Show more
RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires social engineering a user into connecting to a fake VNC Server. The VNC Viewer application they are using will then hang, until terminated, but no memory leak occurs - the resources are freed once the hung process is terminated and the resource usage is constant during the hang. Only the process that is connected to the fake Server is affected. This is an application bug, not a security issueShow less
1Flexera
1Flexnet Publisher
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.
1Ni
1Ni Pal
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.
1Qualcomm
182Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+179 more
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon I...Show more
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesShow less