← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitolite
1Gitolite
Nov 21, 2024
Nov 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
1Drupal
1Drupal
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blo...Show more
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.Show less
2Debian
Tahoe Lafs
2Debian Linux
Tahoe Lafs
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
1Linux
1Linux Kernel
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results...Show more
A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results in an OOPS.Show less
1Wpmarketplace Project
1Wpmarketplace
Nov 21, 2024
Nov 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_ca...Show more
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.Show less
1Google
1Blink
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.
1Konversation
1Konversation
Nov 21, 2024
Nov 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
konversation before 1.2.3 allows attackers to cause a denial of service.
1Typo3
1Typo3
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
1Typo3
1Typo3
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.
1Ruby Rbot
1Rbot
Nov 21, 2024
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Rbot Reaction plugin allows command execution
1Cisco
4Firepower Services Software For Asa
Firepower Threat DefenseSecure Firewall Management Center+1 more
Aug 11, 2026
Nov 5, 2019
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, rem...Show more
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to insufficient normalization of a text-based payload. An attacker could exploit this vulnerability by sending traffic that contains specifically obfuscated payloads through an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious payloads to protected systems that would otherwise be blocked.Show less
1Cisco
4Firepower Services Software For Asa
Firepower Threat DefenseSecure Firewall Management Center+1 more
Aug 11, 2026
Nov 5, 2019
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, rem...Show more
A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper reassembly of traffic streams. An attacker could exploit this vulnerability by sending crafted streams through an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious requests to protected systems that would otherwise be blocked.Show less
1Clamav
1Clamav
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been p...Show more
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.Show less
1Cisco
1Telepresence Advanced Media Gateway
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d...Show more
A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the lack of input validation in the web application. An attacker could exploit this vulnerability by sending a crafted authenticated HTTP request to the device. An exploit could allow the attacker to stop services on an affected device. The device may become inoperable and results in a denial of service (DoS) condition.Show less
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.
4Fedoraproject
OpensusePhp Gettext Project+1 more
4Enterprise Linux
FedoraLeap+1 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
3Fedoraproject
RedhatReviewboard
4Djblets
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
1Arm
2Mbed Mqtt
Mbed Os
Jun 17, 2026
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQTTDeserialize_publish() to get the length and content of the MQTT topic...Show more
A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQTTDeserialize_publish() to get the length and content of the MQTT topic name. In the function readMQTTLenString(), mqttstring->lenstring.len is a part of user input, which can be manipulated. An attacker can simply change it to a larger value to invalidate the if statement so that the statements inside the if statement are skipped, letting the value of mqttstring->lenstring.data default to zero. Later, curn is accessed, which points to mqttstring->lenstring.data. On an Arm Cortex-M chip, the value at address 0x0 is actually the initialization value for the MSP register. It is highly dependent on the actual firmware. Therefore, the behavior of the program is unpredictable from this time on.Show less
3Debian
RedhatSudo Project
4Debian Linux
Enterprise LinuxShadow+1 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into...Show more
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.Show less
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview