CWE-20
12,941 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,941)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Ucs Director Ucs Director Express For Big DataJun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device...Show more |
1Cisco 2Ucs Director Ucs Director Express For Big DataJun 17, 2026 Apr 15, 2020 N/A· v4 7.3 HIGH· v3 8.5 HIGH· v2 Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device...Show more |
1Cisco 2Ucs Director Ucs Director Express For Big DataJun 17, 2026 Apr 15, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device...Show more |
1Cisco 4Webex Meetings Webex Meetings OnlineWebex Meetings Server+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists...Show more |
1Cisco 1Iot Field Network Director Jun 17, 2026 Apr 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected...Show more |
1Cisco 138831 Firmware Ip Phone 7811 FirmwareIp Phone 7821 Firmware+10 moreJun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS)...Show more |
3Canonical DebianSquid Cache3Debian Linux SquidUbuntu LinuxJun 17, 2026 Apr 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, i...Show more |
1Vmware 1Vrealize Log Insight Jun 17, 2026 Apr 15, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. |
Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. |
1Onlyoffice 1Document Server Jun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite a binary and remotely execute code on a victim's server. |
1Onlyoffice 1Document Server Jun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function to pass parameters to a binary (such as curl or wget) and remotely exec...Show more |
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Apr 15, 2020 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulne...Show more |
2Opensuse Oracle2Leap Vm VirtualboxJun 17, 2026 Apr 15, 2020 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability...Show more |
2Opensuse Oracle2Leap Vm VirtualboxJun 17, 2026 Apr 15, 2020 N/A· v4 7.5 HIGH· v3 4.6 MEDIUM· v2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerabili...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraGit+3 moreJun 17, 2026 Apr 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve password...Show more |
1Lenovo 1System Interface Foundation Jun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed. |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge add...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 14, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-Force ID: 174201. |
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes w...Show more |