CWE-20
12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,891)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id paramet...Show more |
1Windows Optimization Master Project 1Windows Optimization Master Jun 17, 2026 Mar 22, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validat...Show more |
12345 Security Guard Project 12345 Security Guard Jun 17, 2026 Mar 22, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x0022204...Show more |
12345 Security Guard Project 12345 Security Guard Jun 17, 2026 Mar 22, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x0022204...Show more |
12345 Security Guard Project 12345 Security Guard Jun 17, 2026 Mar 22, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222108...Show more |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting. |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution. |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution. |
12345 Security Guard Project 12345 Security Guard Jun 17, 2026 Mar 20, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222098. |
12345 Security Guard Project 12345 Security Guard Jun 17, 2026 Mar 20, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x0022209c. |
12345 Security Guard Project 12345 Security Guard Jun 17, 2026 Mar 20, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222054. |
12345 Security Guard Project 12345 Security Guard Jun 17, 2026 Mar 20, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222...Show more |
2Deadwood Project Maradns Project2Deadwood MaradnsNov 21, 2024 Mar 20, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perfor...Show more |
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to...Show more |
If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.)...Show more |
In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in turn, may allow remote execution of arbitrary code. |
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote ex...Show more |
1Siemens 11Simatic Cp 343 1 Firmware Simatic Cp 443 1 FirmwareSimatic S7 1500 Firmware+8 moreNov 21, 2024 Mar 20, 2018 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3),...Show more |
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file. |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Mar 19, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with...Show more |