← Back
CWE-20

12,941 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,941)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
OpensuseRedhat
8Ansible Engine
Ansible TowerBackports Sle+5 more
Jun 17, 2026
Mar 31, 2020
N/A· v4
5.6 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on...Show more
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.Show less
1Ibm
1Spectrum Protect Plus
Jun 17, 2026
Mar 31, 2020
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.
1Ibm
1Spectrum Protect Plus
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID:...Show more
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966.Show less
1Paessler
1Prtg Network Monitor
Jun 17, 2026
Mar 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Su...Show more
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.Show less
1Sensiolabs
1Symfony
Jun 17, 2026
Mar 30, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a...Show more
In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.Show less
1Tp Link
1Ac1750 Firmware
Jun 17, 2026
Mar 25, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The s...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. The issue results from the lack of proper validation of DNS reponses prior to further processing. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the root user. Was ZDI-CAN-9661.Show less
1Jenkins
1Azure Container Service
Jun 17, 2026
Mar 25, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
1Jenkins
1Openshift Pipeline
Jun 17, 2026
Mar 25, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
1Jenkins
1Pipeline\
Jun 17, 2026
Mar 25, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
1Shihonkanri Plus Goout Project
1Shihonkanri Plus Goout
Jun 17, 2026
Mar 25, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is placed via unspecified vector due to the improper input validation issue.
1Druva
1Insync
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 202...Show more
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 2020).Show less
4Fedoraproject
OpensuseOracle+1 more
4Communications Cloud Native Core Network Function Cloud Native Environment
FedoraLeap+1 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoade...Show more
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.Show less
4Debian
FedoraprojectGoogle+1 more
4Backports
ChromeDebian Linux+1 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
1Asus
1Asuswrt
Nov 21, 2024
Mar 20, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
2Denx
Opensuse
2Leap
U Boot
Jun 17, 2026
Mar 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
3Debian
FedoraprojectRedhat
3Debian Linux
FedoraLibvirt
Jun 17, 2026
Mar 19, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
1Bitcoin
1Bitcoin Core
Nov 21, 2024
Mar 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur. Completing the attack would cost more tha...Show more
Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur. Completing the attack would cost more than a million dollars, and is relevant mainly only in situations where an autonomous system relies solely on an SPV proof for transactions of a greater dollar amount.Show less
1Joomla
1Joomla
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.