CWE-20
12,875 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,875)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service (crash) via a crafted image. |
1Apple 3Icloud Iphone OsSafariMay 13, 2026 Oct 23, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers...Show more |
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar. |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 13, 2026 Oct 23, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "CFNetwork Proxies" component...Show more |
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "AppSandbox" component. It allows attackers to cause a denial of service via a crafted app. |
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "iBooks" component. It allows remote attackers to cause a denial of service (persistent outage) via a crafted iBooks fi...Show more |
2Apt Listbugs Project Debian2Apt Listbugs Debian LinuxMay 13, 2026 Oct 20, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors. |
1F5 8Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+5 moreMay 13, 2026 Oct 20, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when using a client SSL profile with the Session Ticket option enabled may caus...Show more |
1Panasonic 1Kx Hjb1000 Firmware May 13, 2026 Oct 20, 2017 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to delete arbitrary files in a specific directory via unspecified vectors. |
1Paessler 1Prtg Network Monitor May 13, 2026 Oct 20, 2017 N/A· v4 6.7 MEDIUM· v3 6.5 MEDIUM· v2 PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message. |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists wi...Show more |
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the de...Show more |
1Cisco 3Expressway Telepresence ConductorTelepresence Video Communication ServerMay 13, 2026 Oct 19, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cau...Show more |
1Cisco 2Jabber Webex Meeting CenterMay 13, 2026 Oct 19, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential inform...Show more |
1Cisco 1Prime Network Analysis Module May 13, 2026 Oct 19, 2017 N/A· v4 5.3 MEDIUM· v3 6.4 MEDIUM· v2 A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability...Show more |
3Lightbend NettyPlayframework3Netty Play FrameworkPlay FrameworkMay 13, 2026 Oct 18, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and ob...Show more |
An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (host OS crash) because of a missing comparison (of range start to range...Show more |
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution. |
nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified impact via unknown vectors. |
FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter. |