← Back
CWE-20

12,875 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,875)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Struts
May 13, 2026
Sep 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted X...Show more
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.Show less
1Apache
1Struts
May 13, 2026
Sep 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
1Apache
1Struts
May 13, 2026
Sep 20, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process whe...Show more
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.Show less
1Rockwellautomation
41763 L16awa Firmware
1763 L16bbb Firmware1763 L16bwa Firmware+1 more
May 13, 2026
Sep 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. A remote, unauthenticated attacker could send a single, special...Show more
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. A remote, unauthenticated attacker could send a single, specially crafted Programmable Controller Communication Commands (PCCC) packet to the controller that could potentially cause the controller to enter a DoS condition.Show less
1Redhat
1Feedhenry Enterprise Mobile Application Platform
May 13, 2026
Sep 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
1Freeipa
1Freeipa
May 13, 2026
Sep 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeIPA might display user data improperly via vectors involving non-printable characters.
2Debian
Gnome
2Debian Linux
Nautilus
May 13, 2026
Sep 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launche...Show more
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file to have execute permission. The solution is to ask the user to confirm that the file is supposed to be treated as a .desktop file, and then remember the user's answer in the metadata::trusted field.Show less
1Sophos
1Astaro Security Gateway Firmware
May 13, 2026
Sep 19, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.
1Qnap
1Qts
May 13, 2026
Sep 19, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
1Vbulletin
1Vbulletin
May 13, 2026
Sep 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vectors related to an input validation failure.
1Landesk
1Landesk Management Suite
May 13, 2026
Sep 19, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/sm_actionfrm.as...Show more
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/sm_actionfrm.asp or (2) remote/frm_coremainfrm.aspx; or the (3) top parameter to remote/frm_splitfrm.aspx.Show less
1Openwebif Project
1Openwebif
May 13, 2026
Sep 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse packag...Show more
OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications in cases where untrusted users can trigger CallOPKG calls, and these users can enter an arbitrary URL in an input field, even though that input field was only intended for a package name. This threat model may be relevant in the latest versions of third-party products that bundle OpenWebif, i.e., set-top box products. The issue of Trojan horse packages does NOT have security implications in cases where the attacker has full OpenWebif access.Show less
1Freedesktop
1Poppler
May 13, 2026
Sep 17, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.
1Freedesktop
1Poppler
May 13, 2026
Sep 17, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
1Sap
1E Recruiting
May 13, 2026
Sep 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/she receives a link by email to confirm access to the provided email ad...Show more
An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/she receives a link by email to confirm access to the provided email address. However, this measure can be bypassed and attackers can register and confirm email addresses that they do not have access to (candidate_hrobject is predictable and corr_act_guid is improperly validated). Furthermore, since an email address can be registered only once, an attacker could prevent other legitimate users from registering. This is SAP Security Note 2507798.Show less
1Sugarcrm
1Sugarcrm
May 13, 2026
Sep 17, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authe...Show more
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string. Proper input validation has been added to mitigate this issue.Show less
1Linux
1Linux Kernel
May 13, 2026
Sep 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.
1Ibm
1Api Connect
May 13, 2026
Sep 13, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.
1Dlink
1Dir 850l Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allow remote attackers to cause a denial of service (daemon crash) via crafted LAN traffic.
1Microsoft
1Edge
May 13, 2026
Sep 13, 2017
N/A· v4
4.2 MEDIUM· v3
4.0 MEDIUM· v2
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Po...Show more
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8723.Show less