CWE-20
12,848 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,848)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificat...Show more |
Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932. |
1Cisco 1Firesight System Software May 6, 2026 Jul 28, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737. |
1Cisco 1Unified Computing System Performance Manager May 6, 2026 Jul 28, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy078...Show more |
WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows r...Show more |
ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote attackers to spoof the URL display via...Show more |
The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to byp...Show more |
1Siemens 1Simatic Net Pc Software May 6, 2026 Jul 22, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outage) via crafted TCP packets. |
1Siemens 3Simatic Batch Simatic Openpcs 7Simatic WinccMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC P...Show more |
2Canonical Ecryptfs2Ecryptfs Utils Ubuntu LinuxMay 6, 2026 Jul 22, 2016 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive informa...Show more |
2Canonical Ecryptfs2Ecryptfs Utils Ubuntu LinuxMay 6, 2026 Jul 22, 2016 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensi...Show more |
Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain sensitive user information via a crafted app that leverages a "type confusion." |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 Jul 22, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows attackers to access the process list via a crafted app that makes an API call. |
WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site. |
4Fedoraproject HpIsc+1 more9Bind Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Jul 19, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request...Show more |
1Hp 6Intelligent Management Center Application Performance Manager Intelligent Management Center Branch Intelligent Management SystemIntelligent Management Center Endpoint Admission Defense+3 moreMay 6, 2026 Jul 15, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute...Show more |
Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715. |
1Apache 2Amqp 0 X Jms Client Jms Client AmqpMay 6, 2026 Jul 13, 2016 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages...Show more |
1Redhat 7Ceph Ceph Storage MonCeph Storage Osd+4 moreMay 6, 2026 Jul 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix. |
MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not check whether memory allocation succeeds, which allows remote at...Show more |