CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Symantec 1Norton Mobile Security Nov 21, 2024 Jan 8, 2020 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack via specially crafted JavaScript. |
1Technicolor 1Tc7230 Steb Firmware Jun 17, 2026 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the...Show more |
1Symantec 1Norton Mobile Security Nov 21, 2024 Jan 8, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to th...Show more |
1Symantec 1It Management Suite Nov 21, 2024 Jan 8, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0. |
1Kunbus 1Pr100088 Modbus Gateway Firmware Jun 17, 2026 Jan 7, 2020 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166). |
2Gnu Redhat2Cpio Enterprise LinuxJun 17, 2026 Jan 7, 2020 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain fil...Show more |
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen. |
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag. |
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. |
1Rovinbhandari Ftp Project 1Rovinbhandari Ftp Jun 17, 2026 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote attackers to cause a denial of service (daemon crash) via a 0xffff datalen field value. |
1Senkas Kolibri Project 1Senkas Kolibri Nov 21, 2024 Dec 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Dec 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring. |
1Huawei 1M5 Lite 10 Firmware Jun 17, 2026 Dec 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the devic...Show more |
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected device. Successful ex...Show more |
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially...Show more |
1Mi 4Dgnwg03lm Firmware Mccgq01lm FirmwareRtcgq01lm Firmware+1 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack. |
1Mi 5Dgnwg03lm Firmware Mccgq01lm FirmwareRtcgq01lm Firmware+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks. |
1Asus 7As 101 Firmware Dl 101 FirmwareHg100 Firmware+4 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks. |
1Asus 7As 101 Firmware Dl 101 FirmwareHg100 Firmware+4 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack. |
2Debian Gnome2Debian Linux Gnome KeyringNov 21, 2024 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function |