← Back
CWE-20

12,834 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,834)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Windows 10
Windows 8.1Windows Server 2012
May 6, 2026
Feb 10, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Windows Reader in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote attackers to execute arbitrary code via a crafted Reader file, aka "Microsoft Windows Reader Vulnerability."
1Microsoft
3Windows 8.1
Windows Rt 8.1Windows Server 2012
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service outage) via crafted "change batch" data, aka "Windows DLL Loa...Show more
Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service outage) via crafted "change batch" data, aka "Windows DLL Loading Denial of Service Vulnerability."Show less
1Microsoft
1Windows Server 2012
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data,...Show more
The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka "Microsoft Active Directory Federation Services Denial of Service Vulnerability."Show less
1Jasper Project
1Jasper
May 6, 2026
Feb 8, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image.
1Atlassian
1Bamboo
May 6, 2026
Feb 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.
1Atlassian
1Bamboo
May 6, 2026
Feb 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.
1Siemens
1Simatic S7 1500 Cpu Firmware
May 6, 2026
Feb 8, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.
1Siemens
1Simatic S7 1500 Cpu Firmware
May 6, 2026
Feb 8, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102.
2Apple
Google
5Android
Iphone OsMac Os X+2 more
May 6, 2026
Feb 7, 2016
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v...Show more
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.Show less
2Apple
Google
5Android
Iphone OsMac Os X+2 more
May 6, 2026
Feb 7, 2016
N/A· v4
9.8 CRITICAL· v3
8.3 HIGH· v2
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v...Show more
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.Show less
1Isc
1Bind
May 6, 2026
Feb 4, 2016
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted...Show more
rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query.Show less
1Radicale
1Radicale
May 6, 2026
Feb 3, 2016
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.
1Huawei
2E5151 Firmware
E5186 Firmware
May 6, 2026
Feb 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it...Show more
Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to spoof responses via unspecified vectors.Show less
2Mozilla
Opensuse
3Firefox
LeapOpensuse
May 6, 2026
Jan 31, 2016
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
1Cisco
1500 Series Switch Firmware
May 6, 2026
Jan 30, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.
1Prosody
1Prosody
May 6, 2026
Jan 29, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafte...Show more
The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.Show less
1Haxx
1Curl
May 6, 2026
Jan 29, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a remote file name.
1Privoxy
1Privoxy
May 6, 2026
Jan 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
1Privoxy
1Privoxy
May 6, 2026
Jan 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via crafted chunk-encoded content.
1Google
1Chrome
May 6, 2026
Jan 25, 2016
N/A· v4
7.6 HIGH· v3
6.8 MEDIUM· v2
The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote at...Show more
The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of service or possibly have unknown other impact via crafted JavaScript code.Show less