CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections |
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an...Show more |
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a huge value in the hea...Show more |
2Apache Opensuse3Leap Mod FcgidOpensuseNov 21, 2024 Dec 3, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. |
OpenShift cartridge allows remote URL retrieval |
2Debian Freebsd2Debian Linux FreebsdNov 21, 2024 Dec 2, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 FreeBSD: Input Validation Flaw allows local users to gain elevated privileges |
illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishand...Show more |
1Huawei 22Cd10 10 Firmware Cd16 10 FirmwareCd17 10 Firmware+19 moreJun 17, 2026 Nov 29, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the...Show more |
3Debian PuppetRuby Lang5Debian Linux Puppet AgentPuppet Enterprise+2 moreNov 21, 2024 Nov 29, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers vi...Show more |
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The...Show more |
1Hitachienergy 2Relion 650 Firmware Relion 670 FirmwareJun 17, 2026 Nov 27, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of servi...Show more |
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POS...Show more |
2Debian Dhclient Project2Debian Linux DhclientNov 21, 2024 Nov 27, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable. |
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles. |
2Debian Yubico2Debian Linux Pam ModuleNov 21, 2024 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use...Show more |
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitrary commands on the underlying operating system as root. The vulnerabili...Show more |
1Cisco 1Email Security Appliance Firmware Jun 17, 2026 Nov 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected...Show more |
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an attacker would need va...Show more |
1Cisco 1Email Security Appliance Firmware Jun 17, 2026 Nov 26, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulne...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on th...Show more |