CWE-20
12,941 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,941)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical CiscoDebian+1 more4Clam Antivirus Debian LinuxFedora+1 moreJun 17, 2026 May 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device....Show more |
4Canonical CiscoDebian+1 more4Clam Antivirus Debian LinuxFedora+1 moreJun 17, 2026 May 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vul...Show more |
1Sap 1Adaptive Server Enterprise Backup Server Jun 17, 2026 May 12, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Inje...Show more |
Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace to potentially gain elevated privileges. See NCC-ZEP-006 This issue affects: zephyrproject-rtos zeph...Show more |
Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions. |
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-...Show more |
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the...Show more |
IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code...Show more |
1Wavlink 3Wl Wn530hg4 Firmware Wl Wn575a3 FirmwareWl Wn579g3 FirmwareJun 17, 2026 May 7, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the supplied command if there is an active session at the same time. The POST...Show more |
dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by setting the arguments to the activex method. A remote attacker could induc...Show more |
1Eaton 1Intelligent Power Manager Jun 17, 2026 May 7, 2020 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via speciall...Show more |
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter. |
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must...Show more |
1Cisco 1Firepower Device Manager On Box Jun 17, 2026 May 6, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerabili...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 May 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device. The vulnerability is due...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 May 6, 2020 N/A· v4 8.1 HIGH· v3 8.5 HIGH· v2 A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on the file system of an affected device. The vulnerability is due to ins...Show more |
1Cisco 15Adaptive Security Appliance Software Asa 5505 FirmwareAsa 5510 Firmware+12 moreAug 11, 2026 May 6, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to u...Show more |
4Ibm OracleQuarkus+1 more7Hibernate Validator Jboss Enterprise Application PlatformQuarkus+4 moreJun 17, 2026 May 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input s...Show more |
1Netgear 5D6100 Firmware D7800 FirmwareR7100lg Firmware+2 moreNov 21, 2024 May 5, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6100 before 1.0.0.55, D7800 before V1.0.1.24, R7100LG before V1.0.0.32, WNDR4300v1 before 1.0.2.90, and WNDR4500v3 befor...Show more |
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users |