CWE-20
12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,891)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Debian2Debian Linux Traffic ServerNov 21, 2024 Feb 27, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used...Show more |
A denial-of-service issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs when a user uploads a file that includes a hexadecimal Unicode character in the "filename" parameter via Wi-Fi, since th...Show more |
The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demonstrated by fstrim. |
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authen...Show more |
1Seagate 2Blackarmor Nas 110 Firmware Blackarmor Nas 220 FirmwareNov 21, 2024 Feb 23, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php. |
1Cisco 1Unified Customer Voice Portal Nov 21, 2024 Feb 22, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconn...Show more |
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions...Show more |
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code o...Show more |
1Datto 8Alto 2 Firmware Alto 3 FirmwareAlto Imaged Firmware+5 moreNov 21, 2024 Feb 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. |
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. Th...Show more |
1Symantec 4Backup Exec System Recovery Norton 360Norton Ghost+1 moreNov 21, 2024 Feb 19, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a deni...Show more |
2Gnu Redhat4Binutils Enterprise Linux DesktopEnterprise Linux Server+1 moreJun 17, 2026 Feb 18, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial o...Show more |
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header. |
1Hp 1Intelligent Management Center Nov 21, 2024 Feb 15, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found. |
1Hp 1Intelligent Management Center Nov 21, 2024 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found. |
1Hp 1Moonshot Provisioning Manager Appliance Nov 21, 2024 Feb 15, 2018 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. |
1Hp 1Moonshot Provisioning Manager Appliance Nov 21, 2024 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. |
1Hp 1Moonshot Provisioning Manager Appliance Nov 21, 2024 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. |
1Hp 1Matrix Operating Environment Nov 21, 2024 Feb 15, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. |
1Hp 1Matrix Operating Environment Nov 21, 2024 Feb 15, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. |