← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
1Norton Mobile Security
Nov 21, 2024
Jan 8, 2020
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack via specially crafted JavaScript.
1Technicolor
1Tc7230 Steb Firmware
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the...Show more
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the cable modem to port forward the modem's internal TELNET server, allowing external access to a root shell.Show less
1Symantec
1Norton Mobile Security
Nov 21, 2024
Jan 8, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to th...Show more
A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.Show less
1Symantec
1It Management Suite
Nov 21, 2024
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.
1Kunbus
1Pr100088 Modbus Gateway Firmware
Jun 17, 2026
Jan 7, 2020
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166).
2Gnu
Redhat
2Cpio
Enterprise Linux
Jun 17, 2026
Jan 7, 2020
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain fil...Show more
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.Show less
1Litespeedtech
1Openlitespeed
Jun 17, 2026
Jan 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
1Extensis
1Mrsid
Nov 21, 2024
Jan 2, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
2Apache
Docker
2Docker
Geode
Nov 21, 2024
Jan 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.
1Rovinbhandari Ftp Project
1Rovinbhandari Ftp
Jun 17, 2026
Dec 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote attackers to cause a denial of service (daemon crash) via a 0xffff datalen field value.
1Senkas Kolibri Project
1Senkas Kolibri
Nov 21, 2024
Dec 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Dec 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
1Huawei
1M5 Lite 10 Firmware
Jun 17, 2026
Dec 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the devic...Show more
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may lead to malicious code execution.Show less
1Huawei
1P30 Firmware
Jun 17, 2026
Dec 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected device. Successful ex...Show more
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected device. Successful exploit may cause the function will be disabled.Show less
1Redhat
1Ceph Storage
Jun 17, 2026
Dec 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially...Show more
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.Show less
1Mi
4Dgnwg03lm Firmware
Mccgq01lm FirmwareRtcgq01lm Firmware+1 more
Jun 17, 2026
Dec 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.
1Mi
5Dgnwg03lm Firmware
Mccgq01lm FirmwareRtcgq01lm Firmware+2 more
Jun 17, 2026
Dec 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
1Asus
7As 101 Firmware
Dl 101 FirmwareHg100 Firmware+4 more
Jun 17, 2026
Dec 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
1Asus
7As 101 Firmware
Dl 101 FirmwareHg100 Firmware+4 more
Jun 17, 2026
Dec 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.
2Debian
Gnome
2Debian Linux
Gnome Keyring
Nov 21, 2024
Dec 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function