← Back
CWE-20

12,908 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,908)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
1Sas
1Sas Drug Development
Nov 21, 2024
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.
1Openmpt
1Libopenmpt
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.
2Openmpt
Opensuse
2Leap
Libopenmpt
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
libopenmpt before 0.3.13 allows a crash with malformed MED files.
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
1Apache
1Virtual Computing Lab
Nov 21, 2024
Jul 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an a...Show more
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementation of that function. The implementation of strtotime at the time the issue was discovered appeared to be resistant to a malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.Show less
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
1Zendesk
1Samlr
Nov 21, 2024
Jul 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
1Qualcomm
38Ipq4019 Firmware
Ipq8064 FirmwareIpq8074 Firmware+35 more
Jun 17, 2026
Jul 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voi...Show more
improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24Show less
1Haproxy
1Proxyprotocol
Jun 17, 2026
Jul 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webserver panic and daemon...Show more
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webserver panic and daemon crash) via a crafted HAProxy PROXY v2 request with truncated source/destination address data.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jul 23, 2019
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and...Show more
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jul 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Jul 23, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When...Show more
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Jul 23, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be...Show more
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jul 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decl...Show more
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious extension. This vulnerability affects Firefox < 67.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jul 23, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow...Show more
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.Show less
1Cat Runner\
1 Decorate Home Project
Jun 17, 2026
Jul 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' sco...Show more
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.Show less