← Back
CWE-20

12,908 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,908)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
2.8 LOW· v3
3.3 LOW· v2
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
2Jolokia
Redhat
2Jolokia
Openstack
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer header...Show more
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.Show less
2Apache
Redhat
3Activemq
Jboss A MqJboss Fuse
Nov 21, 2024
Aug 1, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service...Show more
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.8 MEDIUM· v3
6.6 MEDIUM· v2
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).