← Back
CWE-20

12,897 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,897)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 1, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a system crash.
1Netapp
1Clustered Data Ontap
Jun 17, 2026
Feb 1, 2019
N/A· v4
4.4 MEDIUM· v3
3.5 LOW· v2
Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerabil...Show more
Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerability will allow a remote authenticated attacker to cause a Denial of Service (DoS) on affected versions of clustered Data ONTAP configured for multiprotocol access.Show less
1Google
1Android
Jun 17, 2026
Jan 31, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of priv...Show more
NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.Show less
1Titanhq
1Spamtitan
Nov 21, 2024
Jan 30, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the appl...Show more
TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the application.Show less
1Draeger
4Delta Xl Firmware
Infinity Delta FirmwareInfinity Explorer C700 Firmware+1 more
Nov 21, 2024
Jan 28, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. By repeatedly sending...Show more
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. By repeatedly sending the malformed network packet, an attacker may be able to disrupt patient monitoring by causing the monitor to repeatedly reboot until it falls back to default configuration and loses network connectivity.Show less
1Redhat
1Ceph
Nov 21, 2024
Jan 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
2Debian
Mumble
2Debian Linux
Mumble
Nov 21, 2024
Jan 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a messag...Show more
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.Show less
2Debian
Postgis
2Debian Linux
Postgis
Nov 21, 2024
Jan 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTR...Show more
PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty geometries are mishandled.Show less
1Cisco
1Enterprise Nfv Infrastructure Software
Jun 17, 2026
Jan 24, 2019
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vul...Show more
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation in the affected software. An attacker could exploit this vulnerability by sending crafted commands to the affected device. An exploit could allow the attacker to gain shell access with a nonroot user account to the underlying Linux operating system on the affected device and potentially access system configuration files with sensitive information. This vulnerability only affects console connections from CIMC. It does not apply to remote connections, such as telnet or SSH.Show less
1Cisco
2Rv320 Firmware
Rv325 Firmware
Jun 17, 2026
Jan 24, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected devic...Show more
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.Show less
1Cisco
8Sd Wan
Vbond OrchestratorVedge 1000 Firmware+5 more
Jun 17, 2026
Jan 24, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input...Show more
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the save command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the save command in the CLI of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying operating system of an affected device and escalate their privileges to the root user.Show less
1Cisco
8Sd Wan
Vbond OrchestratorVedge 1000 Firmware+5 more
Jun 17, 2026
Jan 24, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to proper...Show more
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the group configuration. An attacker could exploit this vulnerability by writing a crafted file to the directory where the user group configuration is located in the underlying operating system. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.Show less
1Apache
1Airflow
Nov 21, 2024
Jan 23, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.
2Debian
Drupal
2Debian Linux
Drupal
Jun 17, 2026
Jan 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted...Show more
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.Show less
2Gnu
Opensuse
2Glibc
Leap
Nov 21, 2024
Jan 21, 2019
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applicat...Show more
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.Show less
1Qualcomm
13Mdm9206 Firmware
Mdm9607 FirmwareMsm8909w Firmware+10 more
Jun 17, 2026
Jan 18, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD...Show more
Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 800, SD 810Show less
1Qualcomm
21Mdm9206 Firmware
Mdm9607 FirmwareMdm9635m Firmware+18 more
Nov 21, 2024
Jan 18, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 2...Show more
Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM630, SDM660, SDX24Show less
3Debian
IscRedhat
8Bind
Debian LinuxEnterprise Linux Desktop+5 more
Nov 21, 2024
Jan 16, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructe...Show more
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.Show less
1Hitachienergy
1Relion 630 Firmware
Nov 21, 2024
Jan 16, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message.
1Drupal
1Drupal
Nov 21, 2024
Jan 15, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file...Show more
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is enabled and allows PATCH requests, and an attacker can get or register a user account on the site with permissions to upload files and to modify the file resource.Show less