CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
gitolite before 1.4.1 does not filter src/ or hooks/ from path names. |
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blo...Show more |
2Debian Tahoe Lafs2Debian Linux Tahoe LafsNov 21, 2024 Nov 7, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval. |
A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results...Show more |
1Wpmarketplace Project 1Wpmarketplace Nov 21, 2024 Nov 6, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_ca...Show more |
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed. |
konversation before 1.2.3 allows attackers to cause a denial of service. |
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services. |
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver. |
Rbot Reaction plugin allows command execution |
1Cisco 4Firepower Services Software For Asa Firepower Threat DefenseSecure Firewall Management Center+1 moreAug 11, 2026 Nov 5, 2019 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, rem...Show more |
1Cisco 4Firepower Services Software For Asa Firepower Threat DefenseSecure Firewall Management Center+1 moreAug 11, 2026 Nov 5, 2019 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, rem...Show more |
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been p...Show more |
1Cisco 1Telepresence Advanced Media Gateway Jun 17, 2026 Nov 5, 2019 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d...Show more |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element. |
4Fedoraproject OpensusePhp Gettext Project+1 more4Enterprise Linux FedoraLeap+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. |
3Fedoraproject RedhatReviewboard4Djblets Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. |
A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQTTDeserialize_publish() to get the length and content of the MQTT topic...Show more |
3Debian RedhatSudo Project4Debian Linux Enterprise LinuxShadow+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into...Show more |
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview |