← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freebsd
1Freebsd
May 6, 2026
Jun 10, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive informati...Show more
The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace.Show less
1Gomlab
1Gom Media Player
May 6, 2026
Jun 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.
1Cisco
1Unified Communications Manager
May 6, 2026
Jun 10, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to (1) read or (2) delete arbitrary files via a crafted URL, aka Bug IDs CSCuo173...Show more
The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to (1) read or (2) delete arbitrary files via a crafted URL, aka Bug IDs CSCuo17302 and CSCuo17199.Show less
1Cisco
1Wireless Lan Controller
May 6, 2026
Jun 8, 2014
N/A· v4
N/A· v3
5.7 MEDIUM· v2
Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a zero value in Cisco Discovery Protocol packet data that is not properly...Show more
Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a zero value in Cisco Discovery Protocol packet data that is not properly handled during SNMP polling, aka Bug ID CSCuo12321.Show less
1Emc
1Documentum Content Server
May 6, 2026
Jun 8, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended...Show more
EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended restrictions on database actions via vectors involving DQL hints.Show less
1Emc
1Documentum Digital Asset Manager
May 6, 2026
Jun 6, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P13 allows remote attackers to conduct Documentum Query Language (DQL) injection attacks and bypass i...Show more
The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P13 allows remote attackers to conduct Documentum Query Language (DQL) injection attacks and bypass intended restrictions on querying objects via a crafted parameter in a query string.Show less
1Copadata
2Zenon Dnp3 Ng Driver
Zenon Dnp3 Process Gateway
May 6, 2026
Jun 5, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow physically proximate attackers to cause a de...Show more
COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow physically proximate attackers to cause a denial of service (infinite loop and process crash) via crafted input over a serial line.Show less
1Copadata
2Zenon Dnp3 Ng Driver
Zenon Dnp3 Process Gateway
May 6, 2026
Jun 5, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow remote attackers to cause a denial of servic...Show more
COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow remote attackers to cause a denial of service (infinite loop and process crash) by sending a crafted DNP3 packet over TCP.Show less
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Jun 4, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.
1Typo3
1Typo3
May 6, 2026
Jun 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing...Show more
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."Show less
2Fedoraproject
Openstack
2Fedora
Keystone
May 6, 2026
Jun 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
1Apache
1Tomcat
May 6, 2026
May 31, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a han...Show more
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.Show less
1Trianglemicroworks
1Scada Data Gateway
May 6, 2026
May 30, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line.
1Trianglemicroworks
1Scada Data Gateway
May 6, 2026
May 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet.
2Oisf
Openinfosecfoundation
2Suricata
Suricata
May 6, 2026
May 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
1Dancer
1Dancer
May 6, 2026
May 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a d...Show more
CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.Show less
1Cisco
1Wide Area Application Services
May 6, 2026
May 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not properly parse SharePoint responses, which allows remote attackers to cause a denial of service (applica...Show more
Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not properly parse SharePoint responses, which allows remote attackers to cause a denial of service (application-optimization handler reload) via a crafted SharePoint application, aka Bug ID CSCue47674.Show less
1Cisco
1Unified Communications Domain Manager
May 6, 2026
May 29, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier allows remote attackers to redirect users to arbit...Show more
Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCun79731.Show less
1Samba
1Samba
May 6, 2026
May 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU a...Show more
The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged response packet that triggers a communication loop, a related issue to CVE-1999-0103.Show less
1Dovecot
1Dovecot
May 6, 2026
May 27, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.