CWE-20 · 13,033 records
Improper Input Validation
CVEs in this class
10,000 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
100Now | CVE-2024-3400Weaponized | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Critical10.0 | KEV | 100.0% | Apr 12, 2024 |
99Now | CVE-2018-7600Weaponized | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because odrupal · drupal · CWE-20 | Critical9.8 | KEV | 100.0% | Mar 29, 2018 |
99Now | CVE-2019-0604Weaponized | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pamicrosoft · sharepoint enterprise server · CWE-20 | Critical9.8 | KEV | 99.9% | Mar 5, 2019 |
99Now | CVE-2022-47966Weaponized | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Sanzohocorp · manageengine access manager plus · CWE-20 | Critical9.8 | KEV | 99.8% | Jan 18, 2023 |
99Now | CVE-2018-0171Weaponized | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attackercisco · ios · CWE-20 | Critical9.8 | KEV | 99.5% | Mar 28, 2018 |
99Now | CVE-2022-24086Weaponized | Adobe Commerce checkout improper input validation leads to remote code executionadobe · commerce · CWE-20 | Critical9.8 | KEV | 99.2% | Feb 16, 2022 |
99Now | CVE-2023-22515Weaponized | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknowatlassian · confluence data center · CWE-20 | Critical9.8 | KEV | 99.2% | Oct 4, 2023 |
99Now | CVE-2017-3881Weaponized | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthecisco · ios · CWE-20 | Critical9.8 | KEV | 99.0% | Mar 17, 2017 |
99Now | CVE-2017-9791Weaponized | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message tapache · struts · CWE-20 | Critical9.8 | KEV | 98.9% | Jul 10, 2017 |
99Now | CVE-2020-1350Weaponized | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows microsoft · windows server 2008 · CWE-20 | Critical10.0 | KEV | 96.7% | Jul 14, 2020 |
98Now | CVE-2017-15944Weaponized | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to executepaloaltonetworks · pan-os · CWE-20 | Critical9.8 | KEV | 98.3% | Dec 11, 2017 |
98Now | CVE-2023-23397Weaponized | Microsoft Outlook Elevation of Privilege Vulnerabilitymicrosoft · 365 apps · CWE-20 | Critical9.8 | KEV | 97.2% | Mar 14, 2023 |
97Now | CVE-2024-21413Weaponized | Microsoft Outlook Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-20 | Critical9.8 | KEV | 94.7% | Feb 13, 2024 |
95Now | CVE-2023-2868Weaponized | Remote Code injection in Barracuda Email Security Gatewaybarracuda · email security gateway 300 firmware · CWE-20 | Critical9.8 | KEV | 87.7% | May 24, 2023 |
94Now | CVE-2009-0927Weaponized | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to eadobe · acrobat reader · CWE-20 | High8.8 | KEV | 96.6% | Mar 19, 2009 |
94Now | CVE-2025-54236Weaponized | Adobe Commerce | Improper Input Validation (CWE-20)adobe · commerce · CWE-20 | Critical9.1 | KEV | 94.5% | Sep 9, 2025 |
94Now | CVE-2020-3161Weaponized | Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerabilitycisco · ip phone 8865 firmware · CWE-20 | Critical9.8 | KEV | 83.9% | Apr 15, 2020 |
92Now | CVE-2017-0148Weaponized | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block · CWE-20 | High8.1 | KEV | 99.4% | Mar 16, 2017 |
92Now | CVE-2016-3714Weaponized | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | High8.4 | KEV | 97.5% | May 5, 2016 |
90Now | CVE-2020-3452Weaponized | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerabilitycisco · adaptive security appliance software · CWE-20 | High7.5 | KEV | 100.0% | Jul 22, 2020 |
90Now | CVE-2018-0296Weaponized | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to causecisco · adaptive security appliance software · CWE-20 | High7.5 | KEV | 99.9% | Jun 7, 2018 |
89Now | CVE-2023-22952Weaponized | In SugarCRM before 12.0.sugarcrm · sugarcrm · CWE-20 | High8.8 | KEV | 80.1% | Jan 11, 2023 |
87Now | CVE-2019-1652Weaponized | Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerabilitycisco · rv320 firmware · CWE-20 | High7.2 | KEV | 95.9% | Jan 24, 2019 |
87Now | CVE-2012-0151Weaponized | The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Semicrosoft · windows 7 · CWE-20 | High7.8 | KEV | 87.7% | Apr 10, 2012 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2024-3400100Now
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
CriticalCVSS 10.0KEVWeaponizedEPSS 100%paloaltonetworks · pan-osApr 12, 2024
- CVE-2018-760099Now
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o
CriticalCVSS 9.8KEVWeaponizedEPSS 100%drupal · drupalMar 29, 2018
- CVE-2019-060499Now
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · sharepoint enterprise serverMar 5, 2019
- CVE-2022-4796699Now
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zohocorp · manageengine access manager plusJan 18, 2023
- CVE-2018-017199Now
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker
CriticalCVSS 9.8KEVWeaponizedEPSS 99%cisco · iosMar 28, 2018
- CVE-2022-2408699Now
Adobe Commerce checkout improper input validation leads to remote code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · commerceFeb 16, 2022
- CVE-2023-2251599Now
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow
CriticalCVSS 9.8KEVWeaponizedEPSS 99%atlassian · confluence data centerOct 4, 2023
- CVE-2017-388199Now
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe
CriticalCVSS 9.8KEVWeaponizedEPSS 99%cisco · iosMar 17, 2017
- CVE-2017-979199Now
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · strutsJul 10, 2017
- CVE-2020-135099Now
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows
CriticalCVSS 10.0KEVWeaponizedEPSS 97%microsoft · windows server 2008Jul 14, 2020
- CVE-2017-1594498Now
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute
CriticalCVSS 9.8KEVWeaponizedEPSS 98%paloaltonetworks · pan-osDec 11, 2017
- CVE-2023-2339798Now
Microsoft Outlook Elevation of Privilege Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 97%microsoft · 365 appsMar 14, 2023
- CVE-2024-2141397Now
Microsoft Outlook Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 95%microsoft · 365 appsFeb 13, 2024
- CVE-2023-286895Now
Remote Code injection in Barracuda Email Security Gateway
CriticalCVSS 9.8KEVWeaponizedEPSS 88%barracuda · email security gateway 300 firmwareMay 24, 2023
- CVE-2009-092794Now
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to e
HighCVSS 8.8KEVWeaponizedEPSS 97%adobe · acrobat readerMar 19, 2009
- CVE-2025-5423694Now
Adobe Commerce | Improper Input Validation (CWE-20)
CriticalCVSS 9.1KEVWeaponizedEPSS 95%adobe · commerceSep 9, 2025
- CVE-2020-316194Now
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 84%cisco · ip phone 8865 firmwareApr 15, 2020
- CVE-2017-014892Now
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
HighCVSS 8.1KEVWeaponizedEPSS 99%microsoft · server message blockMar 16, 2017
- CVE-2016-371492Now
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
HighCVSS 8.4KEVWeaponizedEPSS 97%imagemagick · imagemagickMay 5, 2016
- CVE-2020-345290Now
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 100%cisco · adaptive security appliance softwareJul 22, 2020
- CVE-2018-029690Now
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause
HighCVSS 7.5KEVWeaponizedEPSS 100%cisco · adaptive security appliance softwareJun 7, 2018
- CVE-2023-2295289Now
In SugarCRM before 12.0.
HighCVSS 8.8KEVWeaponizedEPSS 80%sugarcrm · sugarcrmJan 11, 2023
- CVE-2019-165287Now
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
HighCVSS 7.2KEVWeaponizedEPSS 96%cisco · rv320 firmwareJan 24, 2019
- CVE-2012-015187Now
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se
HighCVSS 7.8KEVWeaponizedEPSS 88%microsoft · windows 7Apr 10, 2012