← Back
CWE-20

12,833 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,833)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Live Meeting
LyncLync Basic+1 more
May 6, 2026
Aug 15, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Libr...Show more
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."Show less
1Dell
1Netvault Backup
May 6, 2026
Aug 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
1Bittorrent
1Bootstrap Dht
May 6, 2026
Aug 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."
1Fortinet
1Fortios
May 6, 2026
Aug 11, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.
1Juniper
1Pulse Connect Secure
May 6, 2026
Aug 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, w...Show more
Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.0r13, 7.4 before 7.4r13.5, and 7.1 before 7.1r22.2 and PPS 5.1 before 5.1R5 and 5.0 before 5.0R13, when Hardware Acceleration is enabled, does not properly validate the Finished TLS handshake message, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted Finished message.Show less
1Redhat
1Libuser
May 6, 2026
Aug 11, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc...Show more
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.Show less
1Symantec
1Endpoint Protection Manager
May 6, 2026
Aug 1, 2015
N/A· v4
N/A· v3
8.5 HIGH· v2
Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via a Trojan horse DLL in a client install package.
1Symantec
1Endpoint Protection Manager
May 6, 2026
Aug 1, 2015
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafte...Show more
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename.Show less
1Cisco
1Unified Computing System Central Software
May 6, 2026
Jul 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377.
1Webservice Dic
1Yoyaku
May 6, 2026
Jul 29, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors.
1Lemon S Php
1Gazou Bbs Plus
May 6, 2026
Jul 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LEMON-S PHP Gazou BBS plus before 2.36 allows remote attackers to upload arbitrary HTML documents via vectors involving a crafted image file.
3Google
OpensuseRedhat
5Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 more
May 6, 2026
Jul 23, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to c...Show more
The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript code that makes many createElement calls for IFRAME elements.Show less
1Cisco
1Ios Xr
May 6, 2026
Jul 22, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670.
2Debian
Wireshark
2Debian Linux
Wireshark
May 6, 2026
Jul 22, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash)...Show more
epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions.Show less
1Apache
1Http Server
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, rel...Show more
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.Show less
1Blackberry
1Blackberry Link
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file.
1Ibm
1Infosphere Master Data Management
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
1Ibm
1Db2
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scal...Show more
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.Show less
1Cisco
2Videoscape Distribution Suite For Internet Streaming
Videoscape Distribution Suite Service Broker
May 6, 2026
Jul 16, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4....Show more
Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4.0.0 R4 allow remote attackers to cause a denial of service (device reload) via a crafted HTTP request, aka Bug IDs CSCus79834 and CSCuu63409.Show less
1Siemens
1Sicam Mic Firmware
May 6, 2026
Jul 16, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication and obtain administrative access via unspecified HTTP requests.