CWE-20
12,834 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,834)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Readynet Solutions 2Wrt300n Dd Wrt300n Dd FirmwareMay 6, 2026 Dec 31, 2015 N/A· v4 5.8 MEDIUM· v3 4.3 MEDIUM· v2 ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port. |
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks...Show more |
Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries. |
1Asus 2Wl 330nul Wl 33nul FirmwareMay 6, 2026 Dec 30, 2015 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors. |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade att...Show more |
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015. |
1Adcon 1A840 Telemetry Gateway Base Station Firmware May 6, 2026 Dec 24, 2015 N/A· v4 8.7 HIGH· v3 5.8 MEDIUM· v2 The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading clear...Show more |
The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a denial of service (daemon crash) via a malformed packet. |
1Vmware 2Vcenter Orchestrator Vrealize OrchestratorMay 6, 2026 Dec 21, 2015 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to...Show more |
1Cisco 1Prime Network Services Controller May 6, 2026 Dec 18, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional parameters to an unspecified command, aka Bug ID CSCus99427. |
1Cool Video Gallery Project 1Cool Video Gallery May 6, 2026 Dec 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Width of preview image" and possibly other input fields in the "Video Gal...Show more |
Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors. |
Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package archive. |
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015. |
2Debian Phpmailer Project2Debian Linux PhpmailerMay 6, 2026 Dec 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2...Show more |
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute. |
3Fedoraproject MozillaOpensuse4Fedora FirefoxLeap+1 moreMay 6, 2026 Dec 16, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other i...Show more |
3Fedoraproject MozillaOpensuse4Fedora FirefoxLeap+1 moreMay 6, 2026 Dec 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors. |
The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, ak...Show more |
The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote...Show more |