← Back
CWE-20

12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,891)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Qpid Broker J
Jun 17, 2026
Jun 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB...Show more
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.Show less
1Auth0
1Angular Jwt
Nov 21, 2024
Jun 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whiteli...Show more
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.Show less
5Canonical
DebianFedoraproject+2 more
8Ansible Tower
Debian LinuxEnterprise Linux Desktop+5 more
Nov 21, 2024
Jun 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
2Debian
Linaro
2Debian Linux
Lava
Nov 21, 2024
Jun 19, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
2Debian
Linaro
2Debian Linux
Lava
Nov 21, 2024
Jun 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is r...Show more
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.Show less
1Linaro
1Lava
Nov 21, 2024
Jun 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
1Cantata Project
1Cantata
Nov 21, 2024
Jun 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates...Show more
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).Show less
1Cantata Project
1Cantata
Nov 21, 2024
Jun 19, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba...Show more
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba URL.Show less
1Broadcom
1Privileged Access Manager
Jun 17, 2026
Jun 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.
1Broadcom
1Privileged Access Manager
Jun 17, 2026
Jun 18, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.
2Broadcom
Xceedium
2Privileged Access Manager
Xsuite
Nov 21, 2024
Jun 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
5Canonical
DebianFedoraproject+2 more
8Ansible Tower
Debian LinuxEnterprise Linux Desktop+5 more
Nov 21, 2024
Jun 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jun 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode...Show more
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part" of a (1) From or (2) Sender address.Show less
1Artica
1Pandora Fms
Nov 21, 2024
Jun 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.
1Phpok
1Phpok
Nov 21, 2024
Jun 15, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.
1Ffmpeg
1Ffmpeg
Nov 21, 2024
Jun 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FFmpeg 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to...Show more
An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FFmpeg 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.Show less
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Nov 21, 2024
Jun 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of...Show more
An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.Show less
2Canonical
Point To Point Protocol Project
2Point To Point Protocol
Ubuntu Linux
Dec 3, 2025
Jun 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patc...Show more
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.Show less
1Opcfoundation
1Ua .net Legacy
Nov 21, 2024
Jun 14, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.
1Siemens
9Rfid 181 Eip Firmware
Ruggedcom Wimax FirmwareScalance X200 Firmware+6 more
Nov 21, 2024
Jun 14, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch fa...Show more
A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.Show less