CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Grsecurity2Debian Linux PaxtestNov 21, 2024 Oct 29, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 paxtest handles temporary files insecurely |
1Tiki 1Tikiwiki Cms/groupware Nov 21, 2024 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Tiki Wiki CMS Groupware 5.2 has Local File Inclusion |
mailscanner can allow local users to prevent virus signatures from being updated |
Snoopy before 2.0.0 has a security hole in exec cURL |
Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types. An authenticated, remote attacker could potentially exploit this vulne...Show more |
1Projectfloodlight 1Open Sdn Controller Nov 21, 2024 Oct 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the controller service. This effect is the result of a flaw in OpenFlow protocol p...Show more |
1Projectfloodlight 1Open Sdn Controller Nov 21, 2024 Oct 23, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individual switches from the SDN controller, ca...Show more |
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By...Show more |
In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access inf...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Oct 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API...Show more |
1Sr Freecap Project 1Sr Freecap Jun 17, 2026 Oct 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution. |
1Cisco 1Telepresence Collaboration Endpoint Jun 17, 2026 Oct 16, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to perform command injections. The vulnerability is due to insufficient input validation....Show more |
1Cisco 1Telepresence Collaboration Endpoint Jun 17, 2026 Oct 16, 2019 N/A· v4 4.4 MEDIUM· v3 6.6 MEDIUM· v2 Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to overwrite arbitrary files. The vulnerabilities are due to insufficient permis...Show more |
1Cisco 5Aironet 1540 Firmware Aironet 1560 FirmwareAironet 1800 Firmware+2 moreJun 17, 2026 Oct 16, 2019 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled sta...Show more |
1Cisco 25508 Wireless Lan Controller Firmware 5520 Wireless Lan Controller FirmwareJun 17, 2026 Oct 16, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected de...Show more |
1Cisco 3Aironet 1810 Firmware Aironet 1830 FirmwareAironet 1850 FirmwareJun 17, 2026 Oct 16, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause an affected device to relo...Show more |
An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top.location.href = "/dir_login.asp"' line in a .asp file. This provides a...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Oct 10, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Info...Show more |
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service,...Show more |
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector. |