← Back
CWE-20

12,832 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,832)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
3Expressway Software
Telepresence ConductorTelepresence Video Communication Server Software
May 6, 2026
Mar 13, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause...Show more
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192.Show less
1Emc
2Rsa Certificate Manager
Rsa Registration Manager
May 6, 2026
Mar 12, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message...Show more
EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message with a multipart/* Content-Type header.Show less
2Opensuse
Wireshark
2Opensuse
Wireshark
May 6, 2026
Mar 8, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remot...Show more
The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remote attackers to cause a denial of service (stack memory corruption and application crash) via a crafted packet.Show less
4Apache
AppleCanonical+1 more
5Http Server
Mac Os XMac Os X Server+2 more
May 6, 2026
Mar 8, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Pi...Show more
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.Show less
1Siemens
2Simatic S7 300 Cpu
Simatic S7 300 Cpu Firmware
Jun 2, 2026
Mar 7, 2015
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus.
1Siemens
3Spc4000 Firmware
Spc5000 FirmwareSpc6000 Firmware
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted packets.
1Symantec
1Netbackup Opscenter
May 6, 2026
Mar 6, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaScript code via unspecified vectors.
1Cisco
1Ios Xr
May 6, 2026
Mar 6, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858.
1Cisco
1Ios Xr
May 6, 2026
Mar 6, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192.
6Canonical
DebianLinux+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+12 more
May 6, 2026
Mar 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows...Show more
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.Show less
1Cisco
1Unified Computing System
May 6, 2026
Feb 26, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response p...Show more
The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.Show less
1Zhone Technologies
1Gpon 2520 Firmware
May 6, 2026
Feb 23, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter.
1Mcafee
1Mcafee Agent
May 6, 2026
Feb 23, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO server" option is disabled, allows remote attackers to conduct clickjacking attacks via a crafted web pag...Show more
The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO server" option is disabled, allows remote attackers to conduct clickjacking attacks via a crafted web page, aka an "http-generic-click-jacking" vulnerability.Show less
1Cisco
3Content Security Management Appliance
Email Security Appliance FirmwareWeb Security Appliance
May 6, 2026
Feb 21, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP...Show more
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.Show less
1Almail
1Al Mail32
May 6, 2026
Feb 20, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CREAR AL-Mail32 before 1.13d allows remote attackers to cause a denial of service (application crash) via a (1) CON, (2) AUX, or (3) NUL device name in the filename of an attachment.
1Cisco
1Desktop Collaboration Experience Dx650
May 6, 2026
Feb 20, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local users to execute arbitrary OS commands via an unspecified parameter, aka B...Show more
The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local users to execute arbitrary OS commands via an unspecified parameter, aka Bug ID CSCus38947.Show less
1Adminsystems Cms Project
1Adminsystems Cms
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing...Show more
Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/files/.Show less
1Fastcgi
1Fcgi
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
1Cisco
1Hosted Collaboration Solution
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The SOAP interface in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to obtain access to system-management tools via crafted Challenge SOAP calls, aka Bug ID CSCuc38114.
1Cisco
1Wireless Lan Controller
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device outage) via crafted packets that are improperly handle...Show more
The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device outage) via crafted packets that are improperly handled during rendering of the Signature Events Summary page, aka Bug ID CSCus46861.Show less