CWE-20
12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,891)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions. |
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when pa...Show more |
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS...Show more |
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters. |
1Merge Object Project 1Merge Object Nov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can...Show more |
1Merge Options Project 1Merge Options Nov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can...Show more |
1Umbraengineering 1Merge Recursive Nov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This c...Show more |
1Deep Extend Project 1Deep Extend Nov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can l...Show more |
The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an at...Show more |
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an...Show more |
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an atta...Show more |
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domai...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request. |
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated as a command by the application. In this way, the attacker could execu...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can explo...Show more |
1Siemens 2Siclock Tc100 Firmware Siclock Tc400 FirmwareNov 21, 2024 Jul 3, 2018 N/A· v4 8.2 HIGH· v3 8.5 HIGH· v2 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could cause a Denial-of-Service condition by sending certain packets to...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jul 2, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user...Show more |
An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged fo...Show more |
1Redhat 4Ansible Engine OpenstackVirtualization+1 moreNov 21, 2024 Jul 2, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result. |
Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) vulnerability. An unauthenticated attacker may set up a pseudo base sta...Show more |