← Back
CWE-20

12,867 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,867)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
17km Pac Switched Ethernet Profinet Expansion Module Firmware
May 13, 2026
Aug 30, 2017
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) bro...Show more
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requires a manual restart via the main device to recover.Show less
1Apache
1Ofbiz
May 13, 2026
Aug 30, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template cou...Show more
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01Show less
1Wireshark
1Wireshark
May 13, 2026
Aug 30, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation.
1Ibm
1Cognos Analytics
May 13, 2026
Aug 29, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the...Show more
IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 127583.Show less
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803...Show more
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803.Show less
1Question2answer
1Question2answer
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.
1Apache
1Struts
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
1Foxitsoftware
1Foxit Reader
May 13, 2026
Aug 29, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a mali...Show more
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs JavaScript function. The issue results from the lack of proper validation of user-supplied data, which can lead to writing arbitrary files into attacker controlled locations. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4518.Show less
1Libraw
1Libraw
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a floating point exception in the kodak_radc_load_raw function in dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of service attack.
1Sqlite
1Sqlite
May 13, 2026
Aug 29, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and application crash) via a crafted file.
1Cybozu
1Garoon
May 13, 2026
Aug 29, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input
1Pki Core Project
1Pki Core
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple temporary file creation vulnerabilities in pki-core 10.2.0.
1Kgb Bot Project
1Kgb Bot
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash).
1Fli4l
1Fli4l
May 13, 2026
Aug 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.
1Flightgear
1Flightgear
May 13, 2026
Aug 27, 2017
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree.
1Qpdf Project
1Qpdf
May 13, 2026
Aug 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other im...Show more
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in QPDFObjectHandle::parseInternal in libqpdf/QPDFObjectHandle.cc.Show less
1Htacg
1Tidy
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.
3Debian
FedoraprojectNtp
3Debian Linux
FedoraNtp
May 13, 2026
Aug 24, 2017
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a de...Show more
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.Show less
1Graphicsmagick
1Graphicsmagick
May 13, 2026
Aug 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND chunk with a large length value.