CWE-20
12,897 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,897)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a system crash. |
Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerabil...Show more |
NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of priv...Show more |
TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the appl...Show more |
1Draeger 4Delta Xl Firmware Infinity Delta FirmwareInfinity Explorer C700 Firmware+1 moreNov 21, 2024 Jan 28, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. By repeatedly sending...Show more |
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable. |
2Debian Mumble2Debian Linux MumbleNov 21, 2024 Jan 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a messag...Show more |
2Debian Postgis2Debian Linux PostgisNov 21, 2024 Jan 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTR...Show more |
1Cisco 1Enterprise Nfv Infrastructure Software Jun 17, 2026 Jan 24, 2019 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vul...Show more |
1Cisco 2Rv320 Firmware Rv325 FirmwareJun 17, 2026 Jan 24, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected devic...Show more |
1Cisco 8Sd Wan Vbond OrchestratorVedge 1000 Firmware+5 moreJun 17, 2026 Jan 24, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input...Show more |
1Cisco 8Sd Wan Vbond OrchestratorVedge 1000 Firmware+5 moreJun 17, 2026 Jan 24, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to proper...Show more |
In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object. |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Jan 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted...Show more |
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applicat...Show more |
1Qualcomm 13Mdm9206 Firmware Mdm9607 FirmwareMsm8909w Firmware+10 moreJun 17, 2026 Jan 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD...Show more |
1Qualcomm 21Mdm9206 Firmware Mdm9607 FirmwareMdm9635m Firmware+18 moreNov 21, 2024 Jan 18, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 2...Show more |
3Debian IscRedhat8Bind Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jan 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructe...Show more |
1Hitachienergy 1Relion 630 Firmware Nov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message. |
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file...Show more |