← Back
CWE-20

12,892 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,892)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
1Tl R600vpn Firmware
Nov 21, 2024
Nov 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL can cause the server to stop responding to requests, resulting in down...Show more
An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL can cause the server to stop responding to requests, resulting in downtime for the management portal. An attacker can send either an unauthenticated or authenticated web request to trigger this vulnerability.Show less
1Lenovo
1Xclarity Integrator
Jun 17, 2026
Nov 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.
1Nasm
1Netwide Assembler
Nov 21, 2024
Nov 30, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a...Show more
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.Show less
1Sales & Company Management System Project
1Sales & Company Management System
Nov 21, 2024
Nov 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to que...Show more
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new account with a duplicate username, as demonstrated by use of the test%c2 string when a test account already exists.Show less
1Nodejs
1Node.js
Dec 13, 2024
Nov 28, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostna...Show more
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect.Show less
1Qualcomm
12Msm8996au Firmware
Sd 410 FirmwareSd 412 Firmware+9 more
Nov 21, 2024
Nov 28, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Missing validation check on CRL issuer name in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 410/12, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 810, SD 820, SD 820A.
1Qualcomm
5Msm8996au Firmware
Sd 410 FirmwareSd 412 Firmware+2 more
Nov 21, 2024
Nov 28, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU,SD 410/12,SD 820,S...Show more
Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU,SD 410/12,SD 820,SD 820A.Show less
1Terra Master
1Terramaster Operating System
Nov 21, 2024
Nov 27, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.
1Google
1Android
Nov 21, 2024
Nov 27, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper input validation can lead to an improper access to already freed up dci client entries while closing dci...Show more
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper input validation can lead to an improper access to already freed up dci client entries while closing dci client.Show less
1Powerdns
1Dnsdist
Nov 21, 2024
Nov 26, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the addition of a record by dnsdist, for example an OPT record when adding EDNS Client...Show more
An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the addition of a record by dnsdist, for example an OPT record when adding EDNS Client Subnet, might result in the trailing data being smuggled to the backend as a valid record while not seen by dnsdist. This is an issue when dnsdist is deployed as a DNS Firewall and used to filter some records that should not be received by the backend. This issue occurs only when either the 'useClientSubnet' or the experimental 'addXPF' parameters are used when declaring a new backend.Show less
1Totolink
1A3002ru Firmware
Nov 21, 2024
Nov 26, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
1Zblogcn
1Z Blogphp
Nov 21, 2024
Nov 26, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the software maintainer disputes that this is a vulnerability
1Httl Project
1Httl
Nov 21, 2024
Nov 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsafely when configured without an xml.codec= setting.
1Httl Project
1Httl
Nov 21, 2024
Nov 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when configured with an xml.codec=httl.spi.codecs.XstreamCodec setting.
1Eclipse
1Mosquitto
Nov 21, 2024
Nov 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that should otherwise not...Show more
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that should otherwise not be reachable and Mosquitto will exit.Show less
1Google
1Android
Jun 17, 2026
Nov 14, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution...Show more
In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112859604Show less
1Google
1Android
Jun 17, 2026
Nov 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary DoS with no additional execution privileges needed. User interaction is...Show more
In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary DoS with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-68664359Show less
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Jun 17, 2026
Nov 14, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Nov 14, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.