CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image. |
3Apache OracleRedhat3Jboss Enterprise Application Platform Santuario Xml Security For JavaWeblogic ServerJun 17, 2026 Aug 23, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a m...Show more |
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This is...Show more |
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion. |
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Nov 21, 2024 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. |
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting coll...Show more |
1Ad Inserter Project 1Ad Inserter Jun 17, 2026 Aug 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. |
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec. |
1Getshortcodes 1Shortcodes Ultimate Nov 21, 2024 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode. |
1Memphis Documents Library Project 1Memphis Documents Library Nov 21, 2024 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion. |
1Memphis Documents Library Project 1Memphis Documents Library Nov 21, 2024 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. |
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. |
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. |
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder. |
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text. |
1Cisco 1Enterprise Network Function Virtualization Infrastructure Sofware Jun 17, 2026 Aug 21, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operat...Show more |
1Cisco 3Integrated Management Controller Supervisor Ucs DirectorUcs Director Express For Big DataJun 17, 2026 Aug 21, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attac...Show more |
1Cisco 4Cbr 8 Firmware Remote Phy 120 FirmwareRemote Phy 220 Firmware+1 moreJun 17, 2026 Aug 21, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs beca...Show more |
1Cisco 1Unified Contact Center Express Jun 17, 2026 Aug 21, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a us...Show more |
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability. |