CWE-20
12,833 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,833)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Blue Coat 4Ssl Visibility Appliance Sv1800 Firmware Ssl Visibility Appliance Sv2800 FirmwareSsl Visibility Appliance Sv3800 Firmware+1 moreMay 6, 2026 May 30, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to condu...Show more |
1Cisco 3Headend Digital Broadband Delivery System Headend System ReleaseVideoscape ConductorMay 6, 2026 May 30, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408. |
The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to spoof log entries via a crafted request, aka SAP Security Note 2...Show more |
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitra...Show more |
Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a denial of service (wireless-networking outage) via crafted TCP traffic on the local network, aka Bug ID CSCug67104. |
Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka Bug ID CSCut95810. |
1Cisco 1Unified Web And E Mail Interaction Manager May 6, 2026 May 29, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 SQL injection vulnerability in Cisco Unified Email Interaction Manager (EIM) and Unified Web Interaction Manager (WIM) 9.0(2) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID...Show more |
Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800. |
1Ibm 2Endpoint Manager Family License Metric ToolMay 6, 2026 May 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attacker...Show more |
The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadcast packet. |
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popu...Show more |
The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file up...Show more |
3Fedoraproject OracleSquid Cache4Fedora LinuxSolaris+1 moreMay 6, 2026 May 18, 2015 N/A· v4 N/A· v3 2.6 LOW· v2 Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which...Show more |
1Cisco 1Wide Area Application Services May 6, 2026 May 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMB module in Cisco Wide Area Application Services (WAAS) 6.0(1) allows remote attackers to cause a denial of service (module reload) via an invalid field in a Negotiate Protocol request, aka Bug ID CSCuo75645. |
1Cisco 1Wireless Lan Controller Software May 6, 2026 May 16, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122, and 7.5.x and 7.6.x before 7.6.120 allows remote authenticated users to cause a denial o...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 May 16, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID CSCut19546. |
1Y Cam 18Ycb001 Firmware Ycb002 FirmwareYcb003 Firmware+15 moreMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Orig...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 May 13, 2015 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, ak...Show more |
1Cisco 1Unified Computing System Central Software May 6, 2026 May 7, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961. |
Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName paramet...Show more |