← Back
CWE-20

12,849 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,849)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.
3Canonical
LibarchiveNovell
5Libarchive
Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
1Cisco
1Webex Meetings Server
May 6, 2026
Sep 19, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704.
1Cisco
1Fog Director
May 6, 2026
Sep 18, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368.
1Php
1Php
May 6, 2026
Sep 17, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibl...Show more
ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data.Show less
2Openssl
Oracle
3Linux
OpensslSolaris
May 6, 2026
Sep 16, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that...Show more
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.Show less
1Microsoft
1Exchange Server
May 6, 2026
Sep 14, 2016
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to...Show more
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open Redirect Vulnerability."Show less
1Microsoft
1Internet Explorer
May 6, 2026
Sep 14, 2016
N/A· v4
5.0 MEDIUM· v3
5.1 MEDIUM· v2
Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Pr...Show more
Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."Show less
1Cisco
9Ace 4700 Series Application Control Engine Appliance
Ace 4700 Series Application Control Engine Appliance A1Ace 4700 Series Application Control Engine Appliance A3+6 more
May 6, 2026
Sep 12, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2...Show more
Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2) TLS packets, aka Bug ID CSCvb16317.Show less
1Cisco
1Firesight System Software
May 6, 2026
Sep 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP head...Show more
Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482.Show less
1Aki Null
1Yorufukurou
May 6, 2026
Sep 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing from the CoreText CTFramesetter API on OS X 10.9, which allows remote attackers to cause a denial of...Show more
YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing from the CoreText CTFramesetter API on OS X 10.9, which allows remote attackers to cause a denial of service (application crash) via a crafted emoji character sequence.Show less
1Php
1Php
May 6, 2026
Sep 12, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an...Show more
The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an invalid ISO 8601 time value, as demonstrated by a wddx_deserialize call that mishandles a dateTime element in a wddxPacket XML document.Show less
1Juniper
1Junos
May 6, 2026
Sep 9, 2016
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D40, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R6, 15.1 before 15.1F6 or 15.1R3, and 15.1X...Show more
Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D40, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R6, 15.1 before 15.1F6 or 15.1R3, and 15.1X49 before 15.1X49-D40, when configured with a GRE or IPIP tunnel, allow remote attackers to cause a denial of service (kernel panic) via a crafted ICMP packet.Show less
1Juniper
1Junos
May 6, 2026
Sep 9, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9-S1, 14.1 before 14.1R7, 14.2 before 14.2R6, 15.1 before 15.1F2-S5, 15.1F4 before 15.1F4-S2, 15....Show more
Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9-S1, 14.1 before 14.1R7, 14.2 before 14.2R6, 15.1 before 15.1F2-S5, 15.1F4 before 15.1F4-S2, 15.1R before 15.1R2-S3, 15.1 before 15.1R3, and 15.1X49 before 15.1X49-D40 allow remote attackers to cause a denial of service (kernel crash) via a crafted UDP packet destined to the interface IP address of a 64-bit OS device.Show less
1Cisco
1Webex Wrf Player T29
May 6, 2026
Sep 3, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID CSCva09375.
1Ibm
1Mq Appliance Firmware
May 6, 2026
Sep 2, 2016
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) High Availability command.
1Cisco
1Small Business 220 Series Smart Plus Switches
May 6, 2026
Sep 2, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz7623...Show more
The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238.Show less
2Netgear
Nuuo
4Crystal
Nvrmini 2Nvrsolo+1 more
May 6, 2026
Aug 31, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execut...Show more
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.Show less
2Netgear
Nuuo
3Nvrmini 2
NvrsoloReadynas Surveillance
May 6, 2026
Aug 31, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the...Show more
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Aug 23, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724.