CWE-20
12,906 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,906)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame. |
1Cisco 5Asa 5506 X Firmware Asa 5506h X FirmwareAsa 5506w X Firmware+2 moreJun 17, 2026 Jul 10, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot u...Show more |
All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made. |
1Americasarmy 1Proving Grounds Nov 21, 2024 Jul 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplificat...Show more |
main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the address/port were 127.0.0.1:80:443, which is later truncated to 127.0.0.1:...Show more |
2Libpng Netapp2Active Iq Unified Manager LibpngJun 9, 2025 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libpng before 1.6.32 does not properly check the length of chunks against the user limit. |
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000205F. |
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421. |
1Quest 1Kace Systems Management Appliance Jun 17, 2026 Jul 8, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface. |
1Cisco 1Email Security Appliance Jun 17, 2026 Jul 6, 2019 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerabili...Show more |
1Cisco 1Email Security Appliance Jun 17, 2026 Jul 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulner...Show more |
A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected sy...Show more |
1Cisco 1Enterprise Nfv Infrastructure Software Jun 17, 2026 Jul 6, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite or read arbitrary files on the underlying operating system...Show more |
1Cisco 57Esw2 350g52dc Firmware Esw2 550x48dc FirmwareSf200 24 Firmware+54 moreJun 17, 2026 Jul 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. T...Show more |
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances. |
1Cisco 1Application Policy Infrastructure Controller Jun 17, 2026 Jul 4, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker to escalate privileges to root on an affe...Show more |
1Cisco 2Asyncos Web Security ApplianceJun 17, 2026 Jul 4, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient...Show more |
1Cisco 2Asyncos Web Security ApplianceJun 17, 2026 Jul 4, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected de...Show more |
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2. |
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. |