← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Limesurvey
1Limesurvey
Jun 17, 2026
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
3Apache
OracleRedhat
3Jboss Enterprise Application Platform
Santuario Xml Security For JavaWeblogic Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a m...Show more
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Aug 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This is...Show more
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4.Show less
1Hbwsl
1Slidedeck 2
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
1Elastic
1Apm Agent
Jun 17, 2026
Aug 22, 2019
N/A· v4
7.2 HIGH· v3
6.4 MEDIUM· v2
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting coll...Show more
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.Show less
1Ad Inserter Project
1Ad Inserter
Jun 17, 2026
Aug 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
1Payeezy
1Wp Payeezy Pay
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
1Getshortcodes
1Shortcodes Ultimate
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
1Memphis Documents Library Project
1Memphis Documents Library
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
1Memphis Documents Library Project
1Memphis Documents Library
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
1Ninjaforms
1Ninja Forms
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
1Ninjaforms
1Ninja Forms
Nov 21, 2024
Aug 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
1Ninjaforms
1Ninja Forms
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
1Sumo
1Google Analyticator
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
1Cisco
1Enterprise Network Function Virtualization Infrastructure Sofware
Jun 17, 2026
Aug 21, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operat...Show more
A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in an NFVIS file-system command. An attacker could exploit this vulnerability by using crafted variables during the execution of an affected command. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying OS.Show less
1Cisco
3Integrated Management Controller Supervisor
Ucs DirectorUcs Director Express For Big Data
Jun 17, 2026
Aug 21, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attac...Show more
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of this vulnerability requires privileged access to an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrator privileges and then sending a malicious request to a certain part of the interface.Show less
1Cisco
4Cbr 8 Firmware
Remote Phy 120 FirmwareRemote Phy 220 Firmware+1 more
Jun 17, 2026
Aug 21, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs beca...Show more
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid administrator access to an affected device could exploit this vulnerability by supplying various CLI commands with crafted arguments. A successful exploit could allow the attacker to run arbitrary commands as the root user, allowing complete compromise of the system.Show less
1Cisco
1Unified Contact Center Express
Jun 17, 2026
Aug 21, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a us...Show more
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker needs valid administrator credentials.Show less
1Fabrix
1Total Security
Nov 21, 2024
Aug 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.