CWE-20
12,875 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,875)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Secure Firewall Management Center May 13, 2026 Nov 16, 2017 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the Server Message Block Version 2 (SMB...Show more |
1Cisco 1Firepower Extensible Operating System May 13, 2026 Nov 16, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the...Show more |
1Trusted Boot Project 1Trusted Boot May 13, 2026 Nov 16, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trusted Platform Module (TPM) by hooking the...Show more |
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports. |
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface (GUI) view and creat...Show more |
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk." |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks. |
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick a user into loading a page containing malicious content, due to how th...Show more |
Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache. For example, this could allow an attacker to provide...Show more |
1Apple 3Iphone Os TvosWatchosMay 13, 2026 Nov 13, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cau...Show more |
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "AppleScript" component. It allows remote attackers to execute arbitrary code via a crafted AppleScript file tha...Show more |
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory con...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 13, 2026 Nov 13, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "StreamingZip" compon...Show more |
An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site. |
An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site. |
1Matroska 3Libebml2 MkcleanMkvalidatorMay 13, 2026 Nov 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. |
1Matroska 3Libebml2 MkcleanMkvalidatorMay 13, 2026 Nov 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. |
1Matroska 3Libebml2 MkcleanMkvalidatorMay 13, 2026 Nov 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. |