← Back
CWE-20

12,834 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,834)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Telepresence Video Communication Server Software
May 6, 2026
Dec 14, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows remote attackers to bypass intended call-reception and call-setu...Show more
The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows remote attackers to bypass intended call-reception and call-setup restrictions by spoofing a user, aka Bug ID CSCuu97283.Show less
1Cisco
1Emergency Responder
May 6, 2026
Dec 13, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.
1Cisco
1Dpc3939 Wireless Residential Voice Gateway Firmware
May 6, 2026
Dec 13, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Dec 11, 2015
N/A· v4
N/A· v3
2.6 LOW· v2
CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL.
1Apple
1Safari
May 6, 2026
Dec 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Safari in Apple iOS before 9.2 allows remote attackers to spoof a URL in the user interface via a crafted web site.
1Apple
2Iphone Os
Tvos
May 6, 2026
Dec 11, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Apple
3Iphone Os
TvosWatchos
May 6, 2026
Dec 11, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Dec 11, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted mach message that is misparsed.
1Microsoft
3Office
Office Compatibility PackWord
May 6, 2026
Dec 9, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processe...Show more
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."Show less
1Microsoft
1Edge
May 6, 2026
Dec 9, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Edge misparses HTTP responses, which allows remote attackers to redirect users to arbitrary web sites via unspecified vectors, aka "Microsoft Edge Spoofing Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Dec 9, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explo...Show more
Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability."Show less
1Microsoft
4Windows 7
Windows 8Windows 8.1+1 more
May 6, 2026
Dec 9, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted .mcl file, aka "Media Center Library Parsing RCE Vulnerabilit...Show more
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted .mcl file, aka "Media Center Library Parsing RCE Vulnerability."Show less
1Microsoft
3Windows 7
Windows Server 2008Windows Vista
May 6, 2026
Dec 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Cod...Show more
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."Show less
1Huawei
1Unified Security Gateway Firmware
May 6, 2026
Dec 7, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
Huawei USG5500, USG2100, USG2200, and USG5100 unified security gateways with software before V300R001C10SPC600, when "DHCP Snooping" is enabled and either "option82 insert" or "option82 rebuild" is enabled on an interfac...Show more
Huawei USG5500, USG2100, USG2200, and USG5100 unified security gateways with software before V300R001C10SPC600, when "DHCP Snooping" is enabled and either "option82 insert" or "option82 rebuild" is enabled on an interface, allow remote attackers to cause a denial of service (reboot) via crafted DHCP packets.Show less
1Google
1Chrome
May 6, 2026
Dec 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrate...Show more
The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.com?-- substring.Show less
1Google
1Android
May 6, 2026
Dec 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which a...Show more
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive.Show less
1Google
1Chrome
May 6, 2026
Dec 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier f...Show more
The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier for remote attackers to spoof Omnibox content via a crafted web site.Show less
1Emc
1Networker
May 6, 2026
Dec 5, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x before 8.2.2.2, and 9.0 before build 407 allows remote attackers to cause a denial of service (process outage) via malformed RPC authentication messages.
1Cisco
1Ios
May 6, 2026
Dec 1, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access...Show more
The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943.Show less
1Huawei
1Espace Firmware
May 6, 2026
Nov 24, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registere...Show more
Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.Show less