← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Unified Web And E Mail Interaction Manager
May 6, 2026
May 20, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
system/egain/chat/entrypoint in Cisco Unified Web and E-mail Interaction Manager 9.0(2) allows remote attackers to have an unspecified impact by injecting a spoofed XML external entity.
1Cisco
1Unified Web And E Mail Interaction Manager
May 6, 2026
May 20, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote attackers to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084.
1Xen
1Xen
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
3.3 LOW· v2
Xen 4.4.x does not properly validate the load address for 64-bit ARM guest kernels, which allows local users to read system memory or cause a denial of service (crash) via a crafted kernel, which triggers a buffer overfl...Show more
Xen 4.4.x does not properly validate the load address for 64-bit ARM guest kernels, which allows local users to read system memory or cause a denial of service (crash) via a crafted kernel, which triggers a buffer overflow.Show less
1Xen
1Xen
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
1.9 LOW· v2
Xen 4.4.x does not properly check alignment, which allows local users to cause a denial of service (crash) via an unspecified field in a DTB header in a 32-bit guest kernel.
1Xen
1Xen
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
3.3 LOW· v2
The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an i...Show more
The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.Show less
1Leon Weber
1Pyxtrlock
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
pyxtrlock before 0.2 does not properly check the return values of the (1) xcb_grab_pointer and (2) xcb_grab_keyboard XCB library functions, which allows physically proximate attackers to gain access to the keyboard or mo...Show more
pyxtrlock before 0.2 does not properly check the return values of the (1) xcb_grab_pointer and (2) xcb_grab_keyboard XCB library functions, which allows physically proximate attackers to gain access to the keyboard or mouse without unlocking the screen via unspecified vectors.Show less
4Canonical
DebianDjangoproject+1 more
4Debian Linux
DjangoOpensuse+1 more
May 6, 2026
May 16, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect atta...Show more
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."Show less
1Cisco
1Ios
May 6, 2026
May 16, 2014
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The ScanSafe module in Cisco IOS 15.3(3)M allows remote attackers to cause a denial of service (device reload) via HTTPS packets that require tower processing, aka Bug ID CSCum97038.
1Cisco
2Ios
Ios Xe
May 6, 2026
May 16, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of serv...Show more
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.Show less
1Microsoft
2Windows Server 2008
Windows Server 2012
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vul...Show more
Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."Show less
1Microsoft
2Windows Server 2008
Windows Server 2012
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Serv...Show more
Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."Show less
1Canonical
2Software Properties
Ubuntu Linux
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repositor...Show more
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.Show less
1Mediawiki
1Mediawiki
May 6, 2026
May 12, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.
1Intra Mart
1Webplatform/appframework
May 6, 2026
May 9, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in WebPlatform / AppFramework 6.0 through 7.2 in NTT DATA INTRAMART intra-mart allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vec...Show more
Open redirect vulnerability in WebPlatform / AppFramework 6.0 through 7.2 in NTT DATA INTRAMART intra-mart allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.Show less
1Isc
1Bind
May 6, 2026
May 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that trigg...Show more
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.Show less
2Canonical
Qemu
2Qemu
Ubuntu Linux
May 6, 2026
May 8, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indic...Show more
hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information.Show less
1Cisco
5Nexus 7000
Nexus 7000 10 SlotNexus 7000 18 Slot+2 more
May 6, 2026
May 7, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.
1Pywbem Project
1Pywbem
May 6, 2026
May 5, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof...Show more
PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less
1Pywbem Project
1Pywbem
May 6, 2026
May 5, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allow remote attackers to cause a denial of service (memory consumption) via crafted H.225 packets, aka Bug ID CSCtq78849.