← Back
CWE-20

12,929 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,929)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Backdropcms
1Backdrop Cms
Jun 17, 2026
Aug 8, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid...Show more
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be uploaded to the server. (This attack is mitigated by the attacker needing the "Synchronize, import, and export configuration" permission, a permission that only trusted administrators should be given. Other preventative measures in Backdrop CMS prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.) Note: This has been disputed by multiple 3rd parties due to advanced permissions that are needed to exploit.Show less
1Cisco
1Adaptive Security Appliance Software
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file w...Show more
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisory.Show less
1Cisco
1Adaptive Security Appliance Software
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file w...Show more
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisory.Show less
1Cisco
2Carrier Routing System
Ios Xr
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.4 HIGH· v3
6.1 MEDIUM· v2
A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the...Show more
A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS-IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending specific link-state PDUs to an affected system to be processed. A successful exploit could allow the attacker to cause incorrect calculations used in the weighted remote shared risk link groups (SRLG) or in the IGP Flexible Algorithm. It could also cause tracebacks to the logs or potentially cause the receiving device to crash the IS–IS process, resulting in a DoS condition.Show less
1Cisco
2Carrier Routing System
Ios Xr
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.4 HIGH· v3
6.1 MEDIUM· v2
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in...Show more
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS–IS area to unexpectedly restart the IS–IS process, resulting in a DoS condition. This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XR Software earlier than Release 6.6.3 and are configured with the IS–IS routing protocol. Cisco has confirmed that this vulnerability affects both Cisco IOS XR 32-bit Software and Cisco IOS XR 64-bit Software.Show less
1Eq 3
1Ccu3 Firmware
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can ob...Show more
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can obtain a session ID from CVE-2019-9583 or a valid guest/user/admin account can start this attack too.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.1 HIGH· v3
8.7 HIGH· v2
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).
1Cisco
11Sf 220 24 Firmware
Sf220 24p FirmwareSf220 48 Firmware+8 more
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insuffici...Show more
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. To send the malicious request, the attacker needs a valid login session in the web management interface as a privilege level 15 user. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to execute arbitrary shell commands with the privileges of the root user.Show less
1Shenzhen Dragon Brothers
1Fb50 Firmware
Jun 17, 2026
Aug 6, 2019
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of...Show more
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Aug 5, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/c...Show more
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).