← Back
CWE-20

12,944 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,944)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eaton
1Easysoft
Jun 17, 2026
Jan 7, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking...Show more
Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The vulnerability arises due to improper validation of user data supplied through E70 file which is causing Type Confusion.Show less
1Eaton
1Easysoft
Jun 17, 2026
Jan 7, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to u...Show more
The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed .E70 file in the application. The vulnerability arises due to improper validation and parsing of the E70 file content by the application.Show less
1Ibm
1Emptoris Sourcing
Jun 17, 2026
Jan 7, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 190987.
1Ninjaforms
1Ninja Forms
Jun 17, 2026
Jan 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
3Debian
OracleUclouvain
3Debian Linux
OpenjpegOutside In Technology
Jun 17, 2026
Jan 5, 2021
N/A· v4
7.8 HIGH· v3
8.3 HIGH· v2
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highes...Show more
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Show less
3Debian
DovecotFedoraproject
3Debian Linux
DovecotFedora
Jun 17, 2026
Jan 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
4Broadcom
FedoraprojectGnu+1 more
8Binutils
Brocade Fabric Operating System FirmwareCloud Backup+5 more
Jun 17, 2026
Jan 4, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application av...Show more
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.Show less
1Sunhater
1Kcfinder
Nov 21, 2024
Jan 1, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.
1Qnap
1Qts
Nov 21, 2024
Dec 31, 2020
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files...Show more
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.Show less
1Exponentcms
1Exponent Cms
Nov 21, 2024
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS before 2.6.0 has improper input validation in fileController.php.
1Exponentcms
1Exponent Cms
Nov 21, 2024
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
1Exponentcms
1Exponent Cms
Nov 21, 2024
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
1Exponentcms
1Exponent Cms
Nov 21, 2024
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
1Exponentcms
1Exponent Cms
Nov 21, 2024
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
1Uri.js Project
1Uri.js
Jun 17, 2026
Dec 31, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at (`@`) character. If the hostname is use...Show more
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at (`@`) character. If the hostname is used in security decisions, the decision may be incorrect. Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior. For example the URL `https://expected-example.com\@observed-example.com` will incorrectly return `observed-example.com` if using an affected version. Patched versions correctly return `expected-example.com`. Patched versions match the behavior of other parsers which implement the WHATWG URL specification, including web browsers and Node's built-in URL class. Version 1.19.4 is patched against all known payload variants. Version 1.19.3 has a partial patch but is still vulnerable to a payload variant.]Show less
1Netgear
1Nms300 Firmware
Jun 17, 2026
Dec 30, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
1Joomla
1Joomla
Jun 17, 2026
Dec 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.
1Hcltech
1Domino
Jun 17, 2026
Dec 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino serve...Show more
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.Show less
1Huawei
4Cloudengine 12800 Firmware
Cloudengine 5800 FirmwareCloudengine 6800 Firmware+1 more
Jun 17, 2026
Dec 24, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may e...Show more
There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.Show less
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Dec 24, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently va...Show more
On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently validate user input, allowing the user read access to the filesystem.Show less