← Back
CWE-20

12,861 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,861)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nvidia
1Gpu Driver
May 13, 2026
May 9, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of ser...Show more
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.Show less
1F5
10Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+7 more
May 13, 2026
May 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.
1Citrix
1Xenmobile Server
May 13, 2026
May 5, 2017
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis...Show more
Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid vulnerability" because an exploitation scenario would involve a man-in-the-middle attack against a TLS sessionShow less
1Ibm
1Websphere Cast Iron Solution
May 13, 2026
May 5, 2017
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce...Show more
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 119516.Show less
2Hp
Openssl
2Openssl
Operations Agent
May 13, 2026
May 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersui...Show more
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.Show less
1Cisco
1Small Business Rv Series Router Firmware
May 13, 2026
May 3, 2017
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability...Show more
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation of the ACL decision made during the ingress connection request to the remote management interface. An attacker could exploit this vulnerability by sending a connection to the management IP address or domain name of the targeted device. A successful exploit could allow the attacker to bypass the configured remote management ACL. This can occur when the Remote Management configuration parameter is set to Disabled. This vulnerability affects Cisco CVR100W Wireless-N VPN Routers running a firmware image prior to 1.0.1.24. Cisco Bug IDs: CSCvc14457.Show less
1Netiq
1Imanager
May 13, 2026
May 3, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.
1Pexip
1Pexip Infinity
May 13, 2026
May 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.
3Debian
FedoraprojectTug
3Debian Linux
FedoraTex Live
May 13, 2026
May 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
1Gnu
1Binutils
May 13, 2026
May 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets les...Show more
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.Show less
1Irfanview
2Fpx
Irfanview
May 13, 2026
Apr 30, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.
3Debian
RedhatXstream
4Debian Linux
FuseJboss Middleware+1 more
May 23, 2025
Apr 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated...Show more
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.Show less
1Justsystems
9Hanako
Hanako PoliceHanako Pro+6 more
May 13, 2026
Apr 28, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST...Show more
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017 trial version allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.Show less
1Seil
5B1 Firmware
Bpv 4 FirmwareX1 Firmware+2 more
May 13, 2026
Apr 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SEIL/x86 Fuji 1.70 to 5.62, SEIL/BPV4 5.00 to 5.62, SEIL/X1 1.30 to 5.62, SEIL/X2 1.30 to 5.62, SEIL/B1 1.00 to 5.62 allows remote attackers to cause a denial of service via specially crafted IPv4 UDP packets.
1Ipa
1Appgoat
May 13, 2026
Apr 28, 2017
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacks via unspecified vectors.
1Gnome
1Gnome Shell
May 13, 2026
Apr 27, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact w...Show more
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.Show less
1Apache
1Hadoop
May 13, 2026
Apr 26, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0.
1Tp Link
2C20i Firmware
C2 Firmware
May 13, 2026
Apr 25, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI.
1Google
1Chrome
May 13, 2026
Apr 24, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Google Chrome prior to 57.0.2987.100 incorrectly handled back-forward navigation, which allowed a remote attacker to display incorrect information for a site via a crafted HTML page.
1Juniper
1Junos
May 13, 2026
Apr 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND p...Show more
On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers and destined to M/MX series routers can result in a PFE (Packet Forwarding Engine) hang or crash.Show less