← Back
CWE-20

12,882 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,882)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002130.
1Cobbler Project
1Cobbler
Nov 21, 2024
Jan 3, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
1B2evolution
1B2evolution
Nov 21, 2024
Jan 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's set...Show more
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.Show less
3Fedoraproject
Netcf ProjectRedhat
3Enterprise Linux
FedoraNetcf
May 13, 2026
Dec 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
1Ksosoft
1Wps Office
May 13, 2026
Dec 28, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
1Flexense
1Sysgauge
May 13, 2026
Dec 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221.
1Tracker Software
1Pdf Xchange Viewer
May 13, 2026
Dec 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.
1Apple
3Iphone Os
Mac Os XTvos
May 13, 2026
Dec 27, 2017
N/A· v4
6.6 MEDIUM· v3
5.6 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass i...Show more
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash).Show less
2Debian
Linux
2Debian Linux
Linux Kernel
May 13, 2026
Dec 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could po...Show more
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service.Show less
1Digium
2Asterisk
Certified Asterisk
May 13, 2026
Dec 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact he...Show more
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and the PJSIP channel driver was used, Asterisk would crash. The severity of this vulnerability is somewhat mitigated if authentication is enabled. If authentication is enabled, a user would have to first be authorized before reaching the crash point.Show less
2Debian
Enigmail
2Debian Linux
Enigmail
May 13, 2026
Dec 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.
1Apple
1Mac Os X
May 13, 2026
Dec 25, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Apple
1Mac Os X
May 13, 2026
Dec 25, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Rockwellautomation
1Factorytalk Alarms And Events
May 13, 2026
Dec 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Ev...Show more
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver service), causing the service to either stall or terminate.Show less
1Huawei
2S5700 Firmware
S6700 Firmware
May 13, 2026
Dec 22, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Huawei S5700 and S6700 with software of V200R005C00 have a DoS vulnerability due to insufficient validation of the Network Quality Analysis (NQA) packets. A remote attacker could exploit this vulnerability by sending mal...Show more
Huawei S5700 and S6700 with software of V200R005C00 have a DoS vulnerability due to insufficient validation of the Network Quality Analysis (NQA) packets. A remote attacker could exploit this vulnerability by sending malformed NQA packets to the target device. Successful exploitation could make the device restart.Show less
1Huawei
1Baggio L03a Firmware
May 13, 2026
Dec 22, 2017
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Some Huawei smartphones with software of BGO-L03C158B003CUSTC158D001 and BGO-L03C331B009CUSTC331D001 have a DoS vulnerability due to insufficient input validation. An attacker could exploit this vulnerability by sending...Show more
Some Huawei smartphones with software of BGO-L03C158B003CUSTC158D001 and BGO-L03C331B009CUSTC331D001 have a DoS vulnerability due to insufficient input validation. An attacker could exploit this vulnerability by sending specially crafted NFC messages to the target device. Successful exploit could make a service crash.Show less
1Huawei
1Ireader
May 13, 2026
Dec 22, 2017
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card.
1Huawei
1Ireader
May 13, 2026
Dec 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An attacker can control app access and load malicious websites created by...Show more
Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An attacker can control app access and load malicious websites created by the attacker, and the code in webpages would be loaded and run.Show less
1Dena
1H2o
May 13, 2026
Dec 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.