← Back
CWE-20

12,861 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,861)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Quest
1Privilege Manager
May 13, 2026
Apr 14, 2017
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFI...Show more
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.Show less
1Wolfcms
1Wolf Cms
May 13, 2026
Apr 14, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally usin...Show more
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality.Show less
1Wolfcms
1Wolf Cms
May 13, 2026
Apr 14, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a...Show more
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.Show less
1Moxa
1Mxview
May 13, 2026
Apr 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.
1Paloaltonetworks
1Traps
May 13, 2026
Apr 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.
1Paloaltonetworks
1Pan Os
May 13, 2026
Apr 14, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.
1Paloaltonetworks
1Pan Os
May 13, 2026
Apr 14, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.
1Novastor
1Novabackup Datacenter
May 13, 2026
Apr 13, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.
1Novastor
1Novabackup Datacenter
May 13, 2026
Apr 13, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.
1Squashfs Project
1Squashfs
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.
1Umbraco
1Umbraco Cms
May 13, 2026
Apr 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.
1Samsung
2Galaxy Note 3 Firmware
Galaxy S6 Firmware
May 13, 2026
Apr 13, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the...Show more
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the http://should-have-been-filtered.example.com/?http://google.com URL.Show less
1Apple
2Mac Os X
Mac Os X Server
May 13, 2026
Apr 13, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
1Huawei
2P7 Firmware
P8 Ale Ul00 Firmware
May 13, 2026
Apr 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) via vectors involving an application that passes crafted inp...Show more
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) via vectors involving an application that passes crafted input to the GPU driver.Show less
2Debian
Wireshark
2Debian Linux
Wireshark
May 13, 2026
Apr 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting addit...Show more
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.Show less
1Unitrends
1Enterprise Backup
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending...Show more
An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.Show less
1Openidc
1Mod Auth Openidc
May 13, 2026
Apr 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which tri...Show more
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.Show less
1Adobe
1Campaign
May 13, 2026
Apr 12, 2017
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database.
1Microsoft
1Onenote
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability."
1Microsoft
4Windows 10
Windows 8.1Windows Server 2012+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
5.8 MEDIUM· v3
6.3 MEDIUM· v2
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly valid...Show more
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, and CVE-2017-0185.Show less