CWE-20
12,945 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,945)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted obj file could lead to information disclosur...Show more |
4Apache DebianNetapp+1 more60Access Manager Active Iq Unified ManagerAgile Engineering Data Management+57 moreJun 17, 2026 Apr 13, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Apr 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input va...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Apr 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input va...Show more |
Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service. |
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several insta...Show more |
sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple user...Show more |
4Debian Exiv2Fedoraproject+1 more4Debian Linux Enterprise LinuxExiv2+1 moreJun 17, 2026 Apr 8, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a cra...Show more |
A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The...Show more |
A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 Apr 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected sy...Show more |
1Cisco 4Rv110w Firmware Rv130 FirmwareRv130w Firmware+1 moreJun 17, 2026 Apr 8, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 Apr 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected sy...Show more |
1Qualcomm 165Csrb31024 Firmware Pm3003a FirmwarePm456 Firmware+162 moreJun 17, 2026 Apr 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before accessing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile |
Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and exit by sending a relay message with a negative length field. Similarly...Show more |
2Linuxfoundation Sylabs2Singularity UmociJun 17, 2026 Apr 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used. |
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that would have normally...Show more |
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing...Show more |
1Apple 4Ipados Iphone OsTvos+1 moreJun 17, 2026 Apr 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted URL may lead to arbitrary javascript code execu...Show more |
2Apple Debian2Debian Linux Mac Os XJun 17, 2026 Apr 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to...Show more |