CWE-20
12,892 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,892)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source. |
1Redhat 1389 Directory Server Nov 21, 2024 Sep 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort. |
2Debian Powerdns3Authoritative Debian LinuxRecursorNov 21, 2024 Sep 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of...Show more |
2Debian Powerdns3Authoritative Debian LinuxRecursorNov 21, 2024 Sep 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of...Show more |
An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an...Show more |
2Debian Powerdns3Authoritative Debian LinuxRecursorNov 21, 2024 Sep 11, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending...Show more |
2Openstack Redhat2Neutron OpenstackNov 21, 2024 Sep 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP add...Show more |
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and ins...Show more |
2Debian Powerdns2Authoritative Debian LinuxNov 21, 2024 Sep 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If...Show more |
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start block. |
1Currency Converter Script Project 1Currency Converter Script Nov 21, 2024 Sep 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface change) via an inverted comma. |
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Denial of Service can occur through the open HTTP interface, aka KONE-04. |
2Ec Cube Gmo Pg2Ec Cube Payment Module Gmo Pg Payment ModuleNov 21, 2024 Sep 7, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) version 2.3.17 and earlier, GMO-PG Payment Module (PG Multi-Payment Service) (2.12) version 3.5.23 and ear...Show more |
2Ivanti Pulsesecure3Connect Secure Pulse Connect SecurePulse Policy SecureJun 17, 2026 Sep 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an ht...Show more |
7Canonical DebianF5+4 more51Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+48 moreJun 17, 2026 Sep 6, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending...Show more |
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to...Show more |
3Debian FedoraprojectRedhat8389 Directory Server Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Sep 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker...Show more |
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated use...Show more |
3Ibm RedhatSalesforce3Api Connect Openshift Container PlatformTough CookieNov 21, 2024 Sep 5, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP heade...Show more |
2Canonical Zsh2Ubuntu Linux ZshNov 21, 2024 Sep 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one. |