← Back
CWE-20

12,833 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,833)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code via a crafted web site.
1Apple
2Iphone Os
Tvos
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly validate IOKit object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Siemens
1Wincc
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-the-middle attackers to cause a denial of service via crafted...Show more
Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-the-middle attackers to cause a denial of service via crafted packets on TCP port 102.Show less
3Canonical
MozillaOpensuse
3Firefox
OpensuseUbuntu Linux
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-h...Show more
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.Show less
1Redhat
1Docker
May 6, 2026
Apr 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks...Show more
The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic. NOTE: this vulnerability exists because of a CVE-2014-5277 regression.Show less
1Cisco
1Ios Xe
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.
1Sap
1Sql Anywhere
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.
2Fedoraproject
Xen
2Fedora
Xen
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via...Show more
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).Show less
1Mozilla
1Firefox
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered pr...Show more
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.Show less
2Debian
Gaia Gis
2Debian Linux
Freexl
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.
2Debian
Gaia Gis
2Debian Linux
Freexl
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbook, related to a "premature EOF."
2Debian
Gaia Gis
2Debian Linux
Freexl
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook.
2Debian
Shibboleth
2Debian Linux
Service Provider
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
2Mercurial
Opensuse
2Mercurial
Opensuse
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
1Foxitsoftware
3Enterprise Reader
Foxit ReaderPhantompdf
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeS...Show more
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.Show less
2Fedoraproject
Mongodb
2Fedora
Mongodb
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
3Debian
File ProjectPhp
3Debian Linux
FilePhp
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, w...Show more
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.Show less
1Cisco
1Wireless Lan Controller Software
May 6, 2026
Mar 28, 2015
N/A· v4
N/A· v3
6.1 MEDIUM· v2
The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a denial of service (device reload) via a malformed password, aka Bug ID CSCu...Show more
The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a denial of service (device reload) via a malformed password, aka Bug ID CSCui57980.Show less
1Cisco
1Nx Os
May 6, 2026
Mar 28, 2015
N/A· v4
N/A· v3
7.9 HIGH· v2
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending...Show more
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.Show less
1Websense
1Triton Ap Email
May 6, 2026
Mar 27, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 allows remote attackers to conduct clickjacking attacks via unspecified vectors.