← Back
CWE-20

12,849 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,849)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Viprinet
1Multichannel Vpn Router 300 Firmware
May 13, 2026
Jan 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the excha...Show more
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows remote attackers to perform a replay attack.Show less
1Viprinet
1Multichannel Vpn Router 300 Firmware
May 13, 2026
Jan 20, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the excha...Show more
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.Show less
1Moodle
1Moodle
May 13, 2026
Jan 20, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
2Fedoraproject
Gnu
2Bash
Fedora
May 13, 2026
Jan 19, 2017
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
1Netbsd
1Netbsd
May 13, 2026
Jan 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HT...Show more
Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.Show less
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to temporarily spoof the cont...Show more
The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to temporarily spoof the contents of the Omnibox (URL bar) via a crafted HTML page containing PDF data.Show less
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the...Show more
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.Show less
1Samsung
1Exynos Fimg2d Driver
May 13, 2026
Jan 18, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.
1Spip
1Spip
May 13, 2026
Jan 18, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it...Show more
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.Show less
2Hpe
Ntp
2Hpux Ntp
Ntp
May 13, 2026
Jan 13, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
1Ntp
1Ntp
May 13, 2026
Jan 13, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.
1Exponentcms
1Exponent Cms
May 6, 2026
Jan 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sa...Show more
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sample=../../files/exploit', which leads to arbitrary code execution.Show less
1Exponentcms
1Exponent Cms
May 6, 2026
Jan 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which l...Show more
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.Show less
1Google
1Android
May 6, 2026
Jan 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote d...Show more
A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31850211.Show less
1Linux
1Linux Kernel
May 6, 2026
Jan 12, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Possible unauthorized memory access in the hypervisor. Lack of input validation could allow hypervisor memory to be accessed by the HLOS. Product: Android. Versions: Kernel 3.18. Android ID: A-31625910. QC-CR#1038173.
1Linux
1Linux Kernel
May 6, 2026
Jan 12, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel 3.18. Android ID: A-31623057. References: QC-CR#1009695.
1Isc
1Bind
May 6, 2026
Jan 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an...Show more
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.Show less
1Isc
1Bind
May 6, 2026
Jan 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related...Show more
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.Show less
4Debian
IscNetapp+1 more
12Bind
Data Ontap EdgeDebian Linux+9 more
May 6, 2026
Jan 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE AN...Show more
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.Show less