CWE-20
12,938 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,938)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 4Cloud Email Security Content Security Management ApplianceEmail Security Appliance+1 moreJun 17, 2026 Mar 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an un...Show more |
1Cisco 4Webex Meetings Webex Meetings OnlineWebex Meetings Server+1 moreJun 17, 2026 Mar 4, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabili...Show more |
1Cisco 4Webex Meetings Webex Meetings OnlineWebex Meetings Server+1 moreJun 17, 2026 Mar 4, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabili...Show more |
Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response. |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Mar 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files...Show more |
1Pdf Image Project 1Pdf Image Jun 17, 2026 Feb 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field. |
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges. |
1Apple 5Ipados Iphone OsMac Os X+2 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. Processing a maliciously crafted string may...Show more |
1Apple 7Icloud IpadosIphone Os+4 moreJun 17, 2026 Feb 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0,...Show more |
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory. |
1Cisco 3Firepower Extensible Operating System Nx OsUcs ManagerJun 17, 2026 Feb 26, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (Do...Show more |
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of...Show more |
1Cisco 4Adaptive Security Appliance Software Firepower Extensible Operating SystemFirepower Threat Defense+1 moreAug 11, 2026 Feb 26, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input vali...Show more |
1Seling 1Visual Access Manager Jun 17, 2026 Feb 26, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to read XML files on the filesystem via the web interface. The PHP page /common/vam_editXml.php do...Show more |
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitr...Show more |
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups....Show more |
1Ge 16Invenia Abus Scan Station Firmware Logiq E10 FirmwareLogiq E9 Firmware+13 moreJun 17, 2026 Feb 20, 2020 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to t...Show more |
2Fedoraproject Moped Project2Fedora MopedNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site sc...Show more |
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. |