← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cryptocat before 2.0.22 has Remote Denial of Service via username
1Redislabs
1Redis
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
1Redislabs
1Redis
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
1Redhat
1Openshift
Nov 21, 2024
Nov 1, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
2Debian
Glpi Project
2Debian Linux
Glpi
Nov 21, 2024
Nov 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
3Fedoraproject
RedhatSensiolabs
3Enterprise Linux
FedoraSymfony
Nov 21, 2024
Nov 1, 2019
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
php-symfony2-Validator has loss of information during serialization
4Debian
GnomeOpensuse+1 more
4Debian Linux
Enterprise LinuxEvince+1 more
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
evince is missing a check on number of pages which can lead to a segmentation fault
1Honeywell
25H2w2gr1 Firmware
H2w2pc1m FirmwareH2w2per3 Firmware+22 more
Jun 17, 2026
Oct 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.
1Call Cc
1Chicken
Nov 21, 2024
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
2Call Cc
Debian
2Chicken
Debian Linux
Nov 21, 2024
Oct 31, 2019
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
2Fedoraproject
Mantisbt
2Fedora
Mantisbt
Nov 21, 2024
Oct 31, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
2Baseurl
Debian
2Debian Linux
Yum
Nov 21, 2024
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
2Debian
Mumble
2Debian Linux
Mumble
Nov 21, 2024
Oct 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mumble: murmur-server has DoS due to malformed client query
2Debian
Transmissionbt
2Debian Linux
Transmission
Nov 21, 2024
Oct 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
1Rpcbind Project
1Rpcbind
Nov 21, 2024
Oct 29, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started.
1Sugarcrm
1Sugarcrm
Nov 21, 2024
Oct 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
1Osgeo
1Mapserver
Nov 21, 2024
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
1Qtparted Project
1Qtparted
Nov 21, 2024
Oct 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
qtparted has insecure library loading which may allow arbitrary code execution