CWE-20
12,864 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Context Service Development Kit May 13, 2026 Jun 13, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device...Show more |
A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the SIP process...Show more |
2Cloudfoundry Pivotal Software3Cloud Foundry Cf Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jun 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions pri...Show more |
1Pivotal Software 1Cloud Foundry Elastic Runtime May 13, 2026 Jun 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSO...Show more |
1Cloudfoundry 2Cf Release Routing ReleaseMay 13, 2026 Jun 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attac...Show more |
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, a different vulnerability than CVE-2017-2181 and CVE-2017-2182. |
1Buffalotech 1Wnc01wh Firmware May 13, 2026 Jun 9, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen via unspecified vectors. |
1Huawei 22S12700 Firmware S2300 FirmwareS2350ei Firmware+19 moreMay 13, 2026 Jun 8, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message. |
The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash). |
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands. |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxMay 13, 2026 Jun 8, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a...Show more |
1Cisco 1Anyconnect Secure Mobility Client May 13, 2026 Jun 8, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Mi...Show more |
dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV). |
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. |
1Ibm 2Maximo Asset Management Maximo Asset Management EssentialsMay 13, 2026 Jun 7, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to...Show more |
IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation. IBM X-Force ID: 117918. |
2Arm Trustedfirmware2Arm Trusted Firmware Trusted Firmware AJun 8, 2026 Jun 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug regist...Show more |
The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names. |
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution. |
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands...Show more |