CWE-20
12,848 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,848)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter. |
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter, related to a "Gateway HTTP Corruption Denial of Service" issue, aka B...Show more |
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter, related to a "Gateway Client List Denial of Service" issue, aka Bug...Show more |
1Cisco 1Cloud Network Automation Provisioner May 6, 2026 Jul 3, 2016 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureMay 6, 2026 Jul 2, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID...Show more |
IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL. |
1Symantec 18Advanced Threat Protection CsapiData Center Security Server+15 moreMay 6, 2026 Jun 30, 2016 N/A· v4 8.4 HIGH· v3 10.0 HIGH· v2 The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP...Show more |
1Symantec 18Advanced Threat Protection CsapiData Center Security Server+15 moreMay 6, 2026 Jun 30, 2016 N/A· v4 8.4 HIGH· v3 10.0 HIGH· v2 The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP...Show more |
1Symantec 18Advanced Threat Protection CsapiData Center Security Server+15 moreMay 6, 2026 Jun 30, 2016 N/A· v4 8.4 HIGH· v3 10.0 HIGH· v2 The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP...Show more |
2Arvidn Opensuse3Leap LibtorrentOpensuseMay 6, 2026 Jun 30, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP response or possibly a (2) UPnP broadcast. |
2Canonical Thekelleys2Dnsmasq Ubuntu LinuxMay 6, 2026 Jun 30, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally. |
1Trend Micro 1Deep Discovery Inspector May 6, 2026 Jun 30, 2016 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Con...Show more |
4Canonical DebianLinux+1 more4Debian Linux Linux KernelSuse Linux Enterprise Real Time Extension+1 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process sta...Show more |
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data. |
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210. |
1Cisco 1Ip Phone 8800 Series Firmware May 6, 2026 Jun 23, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010. |
1Osisoft 1Pi Sql Data Access Server 2016 May 6, 2026 Jun 19, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss) via a message. |
OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message. |
1Cisco 3Rv110w Wireless N Vpn Firewall Firmware Rv130w Wireless N Multifunction Vpn Router FirmwareRv215w Wireless N Vpn Router FirmwareMay 6, 2026 Jun 19, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute ar...Show more |
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors. |