← Back
CWE-20

12,849 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,849)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Connections
May 6, 2026
Sep 26, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
1Google
1Chrome
May 6, 2026
Sep 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of s...Show more
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of service (unsuppressed popup) via a crafted web site.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Apple
4Iphone Os
ItunesSafari+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote attackers to execute arbitrary code via a crafted web site.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attacks and cause a denial of service via unspecified vectors.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privilege...Show more
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.Show less
1Cisco
1Ios
May 6, 2026
Sep 24, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers,...Show more
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.Show less
1Cisco
1Firesight System Software
May 6, 2026
Sep 24, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL,...Show more
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.Show less
1Cisco
1Ios
May 6, 2026
Sep 24, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug I...Show more
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.Show less
1Cisco
1Cloud Services Platform 2100
May 6, 2026
Sep 22, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.
1Mozilla
1Firefox
May 6, 2026
Sep 22, 2016
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by...Show more
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.Show less
1Mozilla
1Firefox
May 6, 2026
Sep 22, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which all...Show more
The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arbitrary code via a crafted web site.Show less
1Cisco
2Ios
Ios Xe
May 6, 2026
Sep 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intende...Show more
The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoofed traffic that matches one of these sessions, aka Bug IDs CSCun94946 and CSCun96847.Show less
1Huawei
4Ac6003 Firmware
Ac6005 FirmwareAc6605 Firmware+1 more
May 6, 2026
Sep 22, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP packets.
3Libarchive
OracleRedhat
10Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 more
May 6, 2026
Sep 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
3Libarchive
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 more
May 6, 2026
Sep 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large...Show more
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.Show less
4Canonical
DebianLibarchive+1 more
6Debian Linux
LibarchiveLinux Enterprise Desktop+3 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left s...Show more
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.Show less