← Back
CWE-20

12,929 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,929)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
4.9 MEDIUM· v3
5.5 MEDIUM· v2
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento...Show more
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3....Show more
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerabil...Show more
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerability could be abused by an authenticated user with the ability to configure the catalog search.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
3.3 LOW· v3
3.6 LOW· v2
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).