← Back
CWE-20

12,864 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,864)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Horde
1Horde Image
May 13, 2026
Jun 21, 2017
N/A· v4
5.7 MEDIUM· v3
4.3 MEDIUM· v2
Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.
1Gnu
1Gdb
May 13, 2026
Jun 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reac...Show more
GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reached. This can, for example, impede efforts to analyze malware with GDB.Show less
1Adobe
1Captivate
May 13, 2026
Jun 20, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.
1Projectsend
1Projectsend
May 13, 2026
Jun 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.
1Apache
1Thrift
May 13, 2026
Jun 16, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
1Dlink
1Dir 605l Firmware
May 13, 2026
Jun 15, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
1Microsoft
1Edge
May 13, 2026
Jun 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted d...Show more
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8523 and CVE-2017-8530.Show less
1Microsoft
1Outlook
May 13, 2026
Jun 15, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
1Apache
1Ranger
May 13, 2026
Jun 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel stack corruption.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.
1Cisco
1Asr 5000 Software
May 13, 2026
Jun 13, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the file check operation of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify arbitrary fi...Show more
A vulnerability in the file check operation of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify arbitrary files on an affected system. More Information: CSCvd73726. Known Affected Releases: 21.0.v0.65839 21.3.M0.67005. Known Fixed Releases: 21.4.A0.67087 21.4.A0.67079 21.4.A0.67013 21.3.M0.67084 21.3.M0.67077 21.3.M0.66994 21.3.J0.66993 21.1.v0.67082 21.1.V0.67083.Show less
1Cisco
1Ultra Services Framework
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system. More Information: CSCvc76652. Know...Show more
A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system. More Information: CSCvc76652. Known Affected Releases: 21.0.0.Show less
1Cisco
1Firesight System
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device. M...Show more
A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device. More Information: CSCvb16413. Known Affected Releases: 6.0.1 6.1.0 6.2.0 6.2.1. Known Fixed Releases: 6.2.1 6.2.0.1 6.1.0.2.Show less
1Cisco
1Email Security Appliance Firmware
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device, as demonstrated...Show more
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device, as demonstrated by the Attachment Filter. More Information: CSCvd34632. Known Affected Releases: 10.0.1-087 9.7.1-066. Known Fixed Releases: 10.0.2-020 9.8.1-015.Show less