CWE-20
12,944 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,944)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking...Show more |
The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to u...Show more |
IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 190987. |
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field. |
3Debian OracleUclouvain3Debian Linux OpenjpegOutside In TechnologyJun 17, 2026 Jan 5, 2021 N/A· v4 7.8 HIGH· v3 8.3 HIGH· v2 A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highes...Show more |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jan 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts. |
4Broadcom FedoraprojectGnu+1 more8Binutils Brocade Fabric Operating System FirmwareCloud Backup+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application av...Show more |
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy. |
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files...Show more |
Exponent CMS before 2.6.0 has improper input validation in fileController.php. |
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php. |
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php. |
Exponent CMS before 2.6.0 has improper input validation in usersController.php. |
Exponent CMS before 2.6.0 has improper input validation in storeController.php. |
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at (`@`) character. If the hostname is use...Show more |
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user. |
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations. |
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino serve...Show more |
1Huawei 4Cloudengine 12800 Firmware Cloudengine 5800 FirmwareCloudengine 6800 Firmware+1 moreJun 17, 2026 Dec 24, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may e...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Dec 24, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently va...Show more |