← Back
CWE-20

12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,891)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wisc
1Htcondor
Nov 21, 2024
Jul 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
1Apache
1Cxf Fediz
Jun 17, 2026
Jul 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when pa...Show more
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.Show less
1Redhat
1Openshift
Nov 21, 2024
Jul 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS...Show more
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS) attack on an Openshift 3.9, or 3.7 Cluster.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 3, 2018
N/A· v4
5.5 MEDIUM· v3
6.6 MEDIUM· v2
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.
1Merge Object Project
1Merge Object
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can...Show more
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.Show less
1Merge Options Project
1Merge Options
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can...Show more
The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.Show less
1Umbraengineering
1Merge Recursive
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This c...Show more
The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.Show less
1Deep Extend Project
1Deep Extend
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can l...Show more
The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.Show less
1Deap Project
1Deap
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an at...Show more
The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.Show less
1Sonos
1Sonos Firmware
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an...Show more
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.Show less
1Roku
1Roku Firmware
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an atta...Show more
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.Show less
1Navercorp
1Whale
Jun 17, 2026
Jul 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domai...Show more
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name.Show less
1Schneider Electric
1U.motion Builder
Jun 17, 2026
Jul 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.
1Schneider Electric
1U.motion
Jun 17, 2026
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated as a command by the application. In this way, the attacker could execu...Show more
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated as a command by the application. In this way, the attacker could execute code, read the stack, or cause a segmentation fault in the running application.Show less
1Schneider Electric
1U.motion Builder
Jun 17, 2026
Jul 3, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can explo...Show more
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.Show less
1Siemens
2Siclock Tc100 Firmware
Siclock Tc400 Firmware
Nov 21, 2024
Jul 3, 2018
N/A· v4
8.2 HIGH· v3
8.5 HIGH· v2
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could cause a Denial-of-Service condition by sending certain packets to...Show more
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could cause a Denial-of-Service condition by sending certain packets to the device, causing potential reboots of the device. The core functionality of the device could be impacted. The time serving functionality recovers when time synchronization with GPS devices or other NTP servers are completed.Show less
1Redhat
1Openshift Container Platform
Nov 21, 2024
Jul 2, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user...Show more
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.Show less
1Zzcms
1Zzcms
Nov 21, 2024
Jul 2, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged fo...Show more
An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged for database access by deleting install.lock.Show less
1Redhat
4Ansible Engine
OpenstackVirtualization+1 more
Nov 21, 2024
Jul 2, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
1Huawei
1Mate 9 Pro
Nov 21, 2024
Jul 2, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) vulnerability. An unauthenticated attacker may set up a pseudo base sta...Show more
Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) vulnerability. An unauthenticated attacker may set up a pseudo base station, and send special malware text message to the phone, causing the mobile phone to fail to make calls and send and receive text messages.Show less