← Back
CWE-20

12,864 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,864)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 13, 2026
Jul 6, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37478824.
1Google
1Android
May 13, 2026
Jul 6, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36991414.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Jul 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging fa...Show more
The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbd_negotiate function.Show less
1Ibm
1Websphere Mq
May 13, 2026
Jul 6, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM X-Force ID: 124354
1Xen
1Xen
May 13, 2026
Jul 5, 2017
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
1Xen
1Xen
May 13, 2026
Jul 5, 2017
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
1Cisco
1Wide Area Application Services
May 13, 2026
Jul 4, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, cau...Show more
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition. More Information: CSCvc57428. Known Affected Releases: 6.3(1). Known Fixed Releases: 6.3(0.143) 6.2(3c)6 6.2(3.22).Show less
1Cisco
1Ios Xr
May 13, 2026
Jul 4, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: C...Show more
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE.Show less
1Cisco
1Ios Xr
May 13, 2026
Jul 4, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Rel...Show more
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2.1.26i.ROUT.Show less
1Bestpractical
1Request Tracker
May 13, 2026
Jul 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a c...Show more
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.Show less
1Puppet
1Mcollective Sshkey Security
May 13, 2026
Jun 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on...Show more
The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "_pub.pem".Show less
1Antiy
1Antivirus Engine
May 13, 2026
Jun 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call.
1Libtiff
1Libtiff
May 13, 2026
Jun 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack.
1Dell
1Emc Vasa Provider Virtual Appliance
May 13, 2026
Jun 29, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.
1Huawei
1P7 L09 Firmware
May 13, 2026
Jun 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
1Opendaylight
1Defense4all
May 13, 2026
Jun 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.
1Teamspeak
1Teamspeak Client
May 13, 2026
Jun 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TeamSpeak Client 3.0.19 allows remote attackers to cause a denial of service (application crash) via the ᗪ Unicode character followed by the ༿ Unicode character.
1Openvpn
1Openvpn
May 13, 2026
Jun 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
1Redhat
1Virtio Win
May 13, 2026
Jun 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP opti...Show more
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP options.Show less
1Cisco
2Evolved Programmable Network Manager
Prime Infrastructure
May 13, 2026
Jun 26, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored...Show more
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file with malicious entries which could allow the attacker to read and write files and execute remote code within the application, aka XML Injection. Cisco Prime Infrastructure software releases 1.1 through 3.1.6 are vulnerable. Cisco EPNM software releases 1.2, 2.0, and 2.1 are vulnerable. Cisco Bug IDs: CSCvc23894 CSCvc49561.Show less