CWE-20
12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,891)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command...Show more |
3Canonical CryptographyRedhat3Openstack Python CryptographyUbuntu LinuxNov 21, 2024 Jul 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_...Show more |
5Cabextract Cabextract ProjectCanonical+2 more8Ansible Tower CabextractDebian Linux+5 moreNov 21, 2024 Jul 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. |
3Debian RedhatSpice Project7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash. |
3Debian RedhatSpice Project7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible c...Show more |
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers...Show more |
1Redhat 2Jboss Bpm Suite Jboss Data Virtualization & ServicesNov 21, 2024 Jul 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to inte...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF protect...Show more |
1Redhat 1Enterprise Virtualization Nov 21, 2024 Jul 27, 2018 N/A· v4 6.3 MEDIUM· v3 2.1 LOW· v2 When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the...Show more |
2Fedoraproject Redhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+3 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password ha...Show more |
1Redhat 2Ansible Tower CloudformsNov 21, 2024 Jul 27, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access...Show more |
2Apache Redhat5Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally al...Show more |
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate an assertion error is triggered causing a...Show more |
2Qemu Redhat3Openstack QemuVirtualizationNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a clien...Show more |
1Redhat 2Ansible Engine VirtualizationNov 21, 2024 Jul 26, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Jul 25, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server. |
1F5 10Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+7 moreJun 17, 2026 Jul 25, 2018 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile. TMM may restart...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Jul 25, 2018 N/A· v4 7.4 HIGH· v3 6.1 MEDIUM· v2 Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sour...Show more |
1Pivotal Software 1Pivotal Application Service Nov 21, 2024 Jul 24, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when s...Show more |
1Tibco 10Silver Fabric Enabler For Spotfire Web Player Spotfire AnalystSpotfire Analytics Platform For Aws+7 moreNov 21, 2024 Jul 24, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script...Show more |