CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hpe 1Superdome Flex Server Firmware Jun 17, 2026 Jan 16, 2020 N/A· v4 5.5 MEDIUM· v3 5.0 MEDIUM· v2 HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and acce...Show more |
1Emerson 9Rx3i Cpe100 Firmware Rx3i Cpe115 FirmwareRx3i Cpe302 Firmware+6 moreJun 17, 2026 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause th...Show more |
1Siemens 26Apogee Modular Building Controller Firmware Apogee Modular Equiment Controller FirmwareApogee Pxc Firmware+23 moreJun 17, 2026 Jan 16, 2020 7.1 HIGH· v4 7.1 HIGH· v3 4.8 MEDIUM· v2 A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8.2 < V2.8.19), APOGEE PXC...Show more |
4Canonical CiscoClamav+1 more4Clamav Debian LinuxEmail Security Appliance Firmware+1 moreJun 17, 2026 Jan 15, 2020 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected devic...Show more |
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows r...Show more |
2Debian Powerdns2Authoritative Debian LinuxNov 21, 2024 Jan 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via crafted query packets. |
1Cisco 1Ironport Web Security Appliance Nov 21, 2024 Jan 15, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks |
1Cisco 1Ironport Web Security Appliance Nov 21, 2024 Jan 15, 2020 N/A· v4 6.4 MEDIUM· v3 3.2 LOW· v2 Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks |
data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jan 14, 2020 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerabili...Show more |
1Microsoft 2.net Core .net FrameworkJun 17, 2026 Jan 14, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context...Show more |
1Microsoft 2.net Core .net FrameworkJun 17, 2026 Jan 14, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context...Show more |
1Kubernetes 1Nginx Ingress Controller Nov 21, 2024 Jan 14, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly. |
A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2. |
1Sap 5Netweaver Internet Communication Manager (kernel) Netweaver Internet Communication Manager (krnl32nuc)Netweaver Internet Communication Manager (krnl32uc)+2 moreJun 17, 2026 Jan 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49 KERNEL 7.21, 7.49, 7...Show more |
1Redhat 1Automatic Bug Reporting Tool Nov 21, 2024 Jan 14, 2020 N/A· v4 7.1 HIGH· v3 7.2 HIGH· v2 abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProb...Show more |
2Huawei Wps2P2 6011 Firmware Wps OfficeNov 21, 2024 Jan 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-t...Show more |
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file fr...Show more |
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files. |
Status2k allows Remote Command Execution in admin/options/editpl.php. |