CWE-20
12,908 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,908)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). |
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). |
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser. |
libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files. |
2Openmpt Opensuse2Leap LibopenmptNov 21, 2024 Jul 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libopenmpt before 0.3.13 allows a crash with malformed MED files. |
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465). |
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). |
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). |
1Apache 1Virtual Computing Lab Nov 21, 2024 Jul 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an a...Show more |
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. |
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name. |
1Qualcomm 38Ipq4019 Firmware Ipq8064 FirmwareIpq8074 Firmware+35 moreJun 17, 2026 Jul 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voi...Show more |
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webserver panic and daemon...Show more |
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and...Show more |
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68. |
1Mozilla 2Firefox ThunderbirdJun 17, 2026 Jul 23, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When...Show more |
1Mozilla 2Firefox ThunderbirdJun 17, 2026 Jul 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be...Show more |
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decl...Show more |
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow...Show more |
1Cat Runner\ 1 Decorate Home Project Jun 17, 2026 Jul 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' sco...Show more |