Skip to content
Noroxi

CWE-20 · 13,033 records

Improper Input Validation

CVEs in this class

10,000 records

  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    paloaltonetworks · pan-osApr 12, 2024

  • Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    drupal · drupalMar 29, 2018

  • A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · sharepoint enterprise serverMar 5, 2019

  • Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    zohocorp · manageengine access manager plusJan 18, 2023

  • A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    cisco · iosMar 28, 2018

  • Adobe Commerce checkout improper input validation leads to remote code execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    adobe · commerceFeb 16, 2022

  • Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    atlassian · confluence data centerOct 4, 2023

  • A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    cisco · iosMar 17, 2017

  • The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · strutsJul 10, 2017

  • A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows

    CriticalCVSS 10.0KEVWeaponizedEPSS 97%

    microsoft · windows server 2008Jul 14, 2020

  • Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    paloaltonetworks · pan-osDec 11, 2017

  • Microsoft Outlook Elevation of Privilege Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    microsoft · 365 appsMar 14, 2023

  • Microsoft Outlook Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    microsoft · 365 appsFeb 13, 2024

  • Remote Code injection in Barracuda Email Security Gateway

    CriticalCVSS 9.8KEVWeaponizedEPSS 88%

    barracuda · email security gateway 300 firmwareMay 24, 2023

  • Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to e

    HighCVSS 8.8KEVWeaponizedEPSS 97%

    adobe · acrobat readerMar 19, 2009

  • Adobe Commerce | Improper Input Validation (CWE-20)

    CriticalCVSS 9.1KEVWeaponizedEPSS 95%

    adobe · commerceSep 9, 2025

  • Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 84%

    cisco · ip phone 8865 firmwareApr 15, 2020

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    HighCVSS 8.1KEVWeaponizedEPSS 99%

    microsoft · server message blockMar 16, 2017

  • The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor

    HighCVSS 8.4KEVWeaponizedEPSS 97%

    imagemagick · imagemagickMay 5, 2016

  • Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    cisco · adaptive security appliance softwareJul 22, 2020

  • A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    cisco · adaptive security appliance softwareJun 7, 2018

  • In SugarCRM before 12.0.

    HighCVSS 8.8KEVWeaponizedEPSS 80%

    sugarcrm · sugarcrmJan 11, 2023

  • Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability

    HighCVSS 7.2KEVWeaponizedEPSS 96%

    cisco · rv320 firmwareJan 24, 2019

  • The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se

    HighCVSS 7.8KEVWeaponizedEPSS 88%

    microsoft · windows 7Apr 10, 2012

All vulnerability classes