CWE-20
12,849 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,849)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Unified Contact Center Express Unified Intelligence CenterMay 6, 2026 Oct 5, 2016 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accou...Show more |
1Cisco 6Ios Ios XeIos Xe 3.2ja+3 moreMay 6, 2026 Oct 5, 2016 N/A· v4 8.1 HIGH· v3 8.3 HIGH· v2 The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption...Show more |
Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089. |
Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device reload) via crafted fields in an H.323 message, aka Bug ID CSCux04257. |
The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of s...Show more |
2Dell Emc3Emc Unisphere Solutions EnablerUnisphereMay 6, 2026 Oct 5, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input...Show more |
2Dell Emc3Emc Unisphere Solutions EnablerUnisphereMay 6, 2026 Oct 5, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via craf...Show more |
1Emc 2Networker Module For Microsoft Applications Replication ManagerMay 6, 2026 Oct 5, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC Networker Module for Microsoft 8.2.x before 8.2.3.6 allows remote RM servers to execute arbitrary co...Show more |
Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote attackers to cause a denial of service (device restart) via an unspecified URL. |
Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authenticated users to cause a denial of service (device restart) via an unspecified command parameter. |
2Debian Unadf Project2Debian Linux UnadfMay 6, 2026 Oct 3, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file. |
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS,...Show more |
3Hp IscOracle5Bind Hp UxLinux+2 moreMay 6, 2026 Sep 28, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure a...Show more |
The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call. |
1Huawei 2Ar Firmware Netengine 16ex FirmwareMay 6, 2026 Sep 26, 2016 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V2...Show more |
3Fedoraproject OpensuseSqlite3Fedora LeapSqliteMay 6, 2026 Sep 26, 2016 N/A· v4 5.9 MEDIUM· v3 4.6 MEDIUM· v2 os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unsp...Show more |
1Openstack 4Mitaka Murano MuranoMurano Dashboard+1 moreMay 6, 2026 Sep 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka)...Show more |
2Canonical File Roller Project2File Roller Ubuntu LinuxMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive. |
2Fedoraproject Redhat3Fedora Jboss Enterprise Application PlatformJboss Enterprise Web ServerMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate el...Show more |
1Ibm 2Spectrum Control Tivoli Storage Productivity CenterMay 6, 2026 Sep 26, 2016 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site. |