← Back
CWE-20

12,832 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,832)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Telepresence Management Suite
May 6, 2026
Feb 18, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug...Show more
The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.Show less
1Xen
1Xen
May 6, 2026
Feb 16, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The vgic_v2_to_sgi function in arch/arm/vgic-v2.c in Xen 4.5.x, when running on ARM hardware with general interrupt controller (GIC) version 2, allows local guest users to cause a denial of service (host crash) by writin...Show more
The vgic_v2_to_sgi function in arch/arm/vgic-v2.c in Xen 4.5.x, when running on ARM hardware with general interrupt controller (GIC) version 2, allows local guest users to cause a denial of service (host crash) by writing an invalid value to the GICD.SGIR register.Show less
1Cisco
1Ios
May 6, 2026
Feb 12, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The IOS Shell in Cisco IOS allows local users to cause a denial of service (device crash) via unspecified commands, aka Bug ID CSCur59696.
1Cisco
1Prime Infrastructure
May 6, 2026
Feb 12, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks...Show more
The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuj42444.Show less
1Cisco
1Unified Ip Phones 9900 Series Firmware
May 6, 2026
Feb 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff) via crafted packets, aka Bug ID CSCuq12139.
1Cisco
1Webex Meetings Server
May 6, 2026
Feb 7, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.
1Cisco
2Unified Ip Phones 9951 Firmware
Unified Ip Phones 9971 Firmware
May 6, 2026
Feb 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.
1Cisco
2Unified Ip Phones 9951 Firmware
Unified Ip Phones 9971 Firmware
May 6, 2026
Feb 7, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790.
1Cisco
1Nx Os
May 6, 2026
Feb 3, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device reload) via a long CLI command, aka Bug ID CSCur54182.
3Debian
OpensusePrivoxy
3Debian Linux
OpensusePrivoxy
May 6, 2026
Feb 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
3Opensuse
OraclePrivoxy
3Opensuse
PrivoxySolaris
May 6, 2026
Feb 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
1Siemens
1Scalance X 200 Series Firmware
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.
1Cisco
1Webex Meetings Server
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
1Apple
1Mac Os X
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (arbitrary-size bzero of kernel memory) via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows local users to gain privileges or spoof directory-service responses via un...Show more
The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows local users to gain privileges or spoof directory-service responses via unspecified vectors.Show less
1Apple
1Mac Os X
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The kernel in Apple OS X before 10.10.2 does not properly validate IODataQueue object metadata fields, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Apple
1Iphone Os
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, which allows attackers to bypass intended first-launch restrictions by...Show more
Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, which allows attackers to bypass intended first-launch restrictions by leveraging access to an enterprise distribution certificate for signing a crafted app.Show less
1Vmware
3Fusion
PlayerWorkstation
May 6, 2026
Jan 29, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a guest OS denial of serv...Show more
The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a guest OS denial of service via unspecified vectors.Show less
1Ferretcms Project
1Ferretcms
May 6, 2026
Jan 27, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file...Show more
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in custom/uploads/.Show less
1Siemens
2Scalance X 300 Series Firmware
Scalance X 408 Firmware
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP pack...Show more
The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets.Show less