← Back
CWE-20

12,834 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,834)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xen
1Xen
May 6, 2026
Jan 22, 2016
N/A· v4
8.5 HIGH· v3
6.9 MEDIUM· v2
The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other i...Show more
The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier (MFN) to the (1) MMUEXT_MARK_SUPER or (2) MMUEXT_UNMARK_SUPER sub-op in the HYPERVISOR_mmuext_op hypercall or (3) unknown vectors related to page table updates.Show less
1Sap
1Hana
May 6, 2026
Jan 20, 2016
N/A· v4
9.3 CRITICAL· v3
8.5 HIGH· v2
The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, related to an unspecified...Show more
The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, related to an unspecified debug function, aka SAP Security Note 2241978.Show less
1Isc
1Bind
May 6, 2026
Jan 20, 2016
N/A· v4
7.0 HIGH· v3
6.6 MEDIUM· v2
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have uns...Show more
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.Show less
1Isc
1Bind
May 6, 2026
Jan 20, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (...Show more
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.Show less
1Ibm
1Tivoli Storage Manager
May 6, 2026
Jan 20, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of servi...Show more
Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.Show less
1Hp
1Arcsight Logger
May 6, 2026
Jan 16, 2016
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
1Hp
1Arcsight Logger
May 6, 2026
Jan 16, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
1Juniper
1Junos
May 6, 2026
Jan 15, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application Layer Gateway (RTSP ALG...Show more
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application Layer Gateway (RTSP ALG) is enabled, allow remote attackers to cause a denial of service (flowd crash) via a crafted RTSP packet.Show less
1Juniper
1Junos
May 6, 2026
Jan 15, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Embedthis Appweb, as used in J-Web in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2X51 before 13.2X51-D20, 13.3 before...Show more
Embedthis Appweb, as used in J-Web in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R8, 14.1 before 14.1R6, and 14.2 before 14.2R5, allows remote attackers to cause a denial of service (J-Web crash) via unspecified vectors.Show less
1Juniper
1Junos
May 6, 2026
Jan 15, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Routing Engine in Juniper Junos OS 13.2R5 through 13.2R8, 13.3R1 before 13.3R8, 13.3R7 before 13.3R7-S3, 14.1R1 before 14.1R6, 14.1R3 before 14.1R3-S9, 14.1R4 before 14.1R4-S7, 14.1X51 before 14.1X51-D65, 14.1X53 bef...Show more
The Routing Engine in Juniper Junos OS 13.2R5 through 13.2R8, 13.3R1 before 13.3R8, 13.3R7 before 13.3R7-S3, 14.1R1 before 14.1R6, 14.1R3 before 14.1R3-S9, 14.1R4 before 14.1R4-S7, 14.1X51 before 14.1X51-D65, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D28, 14.1X53 before 4.1X53-D35, 14.2R1 before 14.2R5, 14.2R3 before 14.2R3-S4, 14.2R4 before 14.2R4-S1, 15.1 before 15.1R3, 15.1F2 before 15.1F2-S2, and 15.1X49 before 15.1X49-D40, when LDP is enabled, allows remote attackers to cause a denial of service (RPD routing process crash) via a crafted LDP packet.Show less
1Gajim
1Gajim
May 6, 2026
Jan 15, 2016
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
4Canonical
DebianIsc+1 more
4Debian Linux
DhcpUbuntu Linux+1 more
May 6, 2026
Jan 14, 2016
N/A· v4
6.5 MEDIUM· v3
5.7 MEDIUM· v2
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
1Firebirdsql
1Firebird
May 6, 2026
Jan 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invalid parameter.
3Fedoraproject
OpensusePython
4Fedora
LeapOpensuse+1 more
May 6, 2026
Jan 13, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
3Canonical
DebianPerl
3Debian Linux
PathtoolsUbuntu Linux
May 6, 2026
Jan 13, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protect...Show more
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.Show less
2Fedoraproject
Openstack
2Fedora
Swift3
May 6, 2026
Jan 13, 2016
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
1Microsoft
1Internet Explorer
May 6, 2026
Jan 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability."
1F5
8Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+5 more
May 6, 2026
Jan 12, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote attackers to cause a deni...Show more
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote attackers to cause a denial of service (Traffic Management Microkernel (TMM) restart) via crafted ICMP packets, related to Path MTU (PMTU) discovery.Show less
1Huawei
1Vcn500
May 6, 2026
Jan 11, 2016
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly invalidate the session ID when an "abnormal exit" occurs, which allows remote attackers to conduct replay...Show more
The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly invalidate the session ID when an "abnormal exit" occurs, which allows remote attackers to conduct replay attacks via the session ID.Show less
1Typo3
1Typo3
May 6, 2026
Jan 8, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."