CWE-20
12,937 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,937)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Coppermine Gallery 1Coppermine Gallery Nov 21, 2024 Feb 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution. |
1Cisco 33Ip Conference Phone 7832 Firmware Ip Conference Phone 7832 With Multiplatform FirmwareIp Conference Phone 8832 Firmware+30 moreJun 17, 2026 Feb 5, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP ph...Show more |
1Cisco 8Video Surveillance 8000p Ip Camera Firmware Video Surveillance 8020 Ip Camera FirmwareVideo Surveillance 8030 Ip Camera Firmware+5 moreJun 17, 2026 Feb 5, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an af...Show more |
3Canonical OpensuseSquid Cache3Leap SquidUbuntu LinuxJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory a...Show more |
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona. |
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. |
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received. |
3Nextcloud OpensuseSuse3Backports Nextcloud ServerSuse Linux Enterprise ServerJun 17, 2026 Feb 4, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. |
2Nextcloud Opensuse2Backports Nextcloud ServerJun 17, 2026 Feb 4, 2020 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes. |
The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code. |
2Arubanetworks Siemens4Airwave Aruba InstantArubaos+1 moreNov 21, 2024 Jan 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass secu...Show more |
1Bitdefender 1Total Security 2020 Jun 17, 2026 Jan 30, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial of service on the affected device. |
1Cisco 57Sf300 08 Firmware Sf300 24 FirmwareSf300 24mp Firmware+54 moreJun 17, 2026 Jan 30, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper vali...Show more |
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged....Show more |
In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the format checks for this use case are only in the graph mode. This issue c...Show more |
IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863. |
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_pr...Show more |
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer. |
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized. |
SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as demonstrated by an admin login. The attacker must use a Parameter Polluti...Show more |