CWE-20
12,832 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,832)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 3Expressway Software Telepresence ConductorTelepresence Video Communication Server SoftwareMay 6, 2026 Mar 13, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause...Show more |
1Emc 2Rsa Certificate Manager Rsa Registration ManagerMay 6, 2026 Mar 12, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message...Show more |
The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remot...Show more |
4Apache AppleCanonical+1 more5Http Server Mac Os XMac Os X Server+2 moreMay 6, 2026 Mar 8, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Pi...Show more |
1Siemens 2Simatic S7 300 Cpu Simatic S7 300 Cpu FirmwareJun 2, 2026 Mar 7, 2015 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus. |
1Siemens 3Spc4000 Firmware Spc5000 FirmwareSpc6000 FirmwareMay 6, 2026 Mar 7, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted packets. |
Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaScript code via unspecified vectors. |
The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858. |
Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192. |
6Canonical DebianLinux+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows...Show more |
The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response p...Show more |
1Zhone Technologies 1Gpon 2520 Firmware May 6, 2026 Feb 23, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter. |
The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO server" option is disabled, allows remote attackers to conduct clickjacking attacks via a crafted web pag...Show more |
1Cisco 3Content Security Management Appliance Email Security Appliance FirmwareWeb Security ApplianceMay 6, 2026 Feb 21, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP...Show more |
CREAR AL-Mail32 before 1.13d allows remote attackers to cause a denial of service (application crash) via a (1) CON, (2) AUX, or (3) NUL device name in the filename of an attachment. |
1Cisco 1Desktop Collaboration Experience Dx650 May 6, 2026 Feb 20, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local users to execute arbitrary OS commands via an unspecified parameter, aka B...Show more |
1Adminsystems Cms Project 1Adminsystems Cms May 6, 2026 Feb 19, 2015 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing...Show more |
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections. |
1Cisco 1Hosted Collaboration Solution May 6, 2026 Feb 19, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SOAP interface in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to obtain access to system-management tools via crafted Challenge SOAP calls, aka Bug ID CSCuc38114. |
The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device outage) via crafted packets that are improperly handle...Show more |