← Back
CWE-20

12,845 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,845)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Puppet
2Puppet Agent
Puppet Enterprise
May 6, 2026
Jun 10, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute ar...Show more
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate.Show less
1Cisco
1Aironet Access Point Software
May 6, 2026
Jun 10, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka Bug ID CSCuy55803.
3Canonical
DebianXmlsoft
3Debian Linux
Libxml2Ubuntu Linux
May 6, 2026
Jun 9, 2016
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a d...Show more
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.Show less
1Hp
3Universal Cmbd Configuration Manager
Universal Cmbd FoundationUniversal Discovery
May 6, 2026
Jun 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Jav...Show more
HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.Show less
1Cisco
1Aironet Access Point Software
May 6, 2026
Jun 8, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via crafted CLI command parameters, aka Bug ID CSCuy64037.
1F5
9Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+6 more
May 6, 2026
Jun 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Traffic Management Microkernel restart) via an SSL alert during the handsh...Show more
Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Traffic Management Microkernel restart) via an SSL alert during the handshake.Show less
2Apache
Ognl Project
2Ognl
Struts
May 6, 2026
Jun 7, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified ve...Show more
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.Show less
1Apache
1Struts
May 6, 2026
Jun 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) opera...Show more
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.Show less
2Debian
Freetype
2Debian Linux
Freetype
May 6, 2026
Jun 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs...Show more
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted font.Show less
1Cisco
1Ip Phone 8800 Series Firmware
May 6, 2026
Jun 4, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via crafted CLI commands, aka Bug ID CSCuz03005.
1Cisco
2Prime Network Analysis Module Software
Prime Virtual Network Analysis Module Software
May 6, 2026
Jun 4, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) allow remote auth...Show more
Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) allow remote authenticated users to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuy21889.Show less
1Cisco
2Prime Network Analysis Module Software
Prime Virtual Network Analysis Module Software
May 6, 2026
Jun 4, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) allow local users...Show more
Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) allow local users to obtain root access via crafted CLI input, aka Bug ID CSCuy21892.Show less
1Lenovo
1Accelerator Application
May 6, 2026
Jun 3, 2016
N/A· v4
7.5 HIGH· v3
9.3 HIGH· v2
UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com.
3Ibm
NovellRedhat
13Enterprise Linux Desktop
Enterprise Linux Hpc Node SupplementaryEnterprise Linux Server+10 more
May 6, 2026
Jun 3, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before...Show more
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.Show less
1Cisco
1Network Analysis Module Software
May 6, 2026
Jun 3, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Prime Network Analysis Module (NAM) before 6.2(1-b) miscalculates IPv6 payload lengths, which allows remote attackers to cause a denial of service (mond process crash and monitoring outage) via crafted IPv6 packets...Show more
Cisco Prime Network Analysis Module (NAM) before 6.2(1-b) miscalculates IPv6 payload lengths, which allows remote attackers to cause a denial of service (mond process crash and monitoring outage) via crafted IPv6 packets, aka Bug ID CSCuy37324.Show less
1Apache
1Qpid Broker J
May 6, 2026
Jun 1, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication at...Show more
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.Show less
1Cisco
4Ios
Ios XeIos Xr+1 more
May 6, 2026
May 29, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outag...Show more
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.Show less
2Fedoraproject
Perl
2Fedora
Perl
May 6, 2026
May 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated...Show more
The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80."Show less
1Cisco
1Ios Xr
May 6, 2026
May 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP por...Show more
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.Show less
1Cisco
1Telepresence Video Communication Server
May 6, 2026
May 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.