CWE-20— Improper Input Validation
11,463 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-20page 91 of 230
- CVE-2018-20835HIGHCVSS 7.5EG 7.52019-04-30
A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same n…
- CVE-2018-20846MEDIUMCVSS 6.5EG 6.52019-06-26
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash…
- CVE-2018-20852MEDIUMCVSS 5.3EG 5.32019-07-13
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by u…
- CVE-2018-20857HIGHCVSS 7.5EG 7.52019-07-26
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
- CVE-2018-20860MEDIUMCVSS 6.5EG 6.52019-07-30
libopenmpt before 0.3.13 allows a crash with malformed MED files.
- CVE-2018-20861MEDIUMCVSS 6.5EG 6.52019-07-30
libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.
- CVE-2018-20863CRITICALCVSS 9.8EG 9.82019-07-30
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
- CVE-2018-20864MEDIUMCVSS 6.5EG 6.52019-07-30
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
- CVE-2018-20869HIGHCVSS 7.8EG 7.82019-07-30
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
- CVE-2018-20873LOWCVSS 3.3EG 3.32019-08-01
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
- CVE-2018-20879MEDIUMCVSS 6.3EG 6.32019-08-01
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
- CVE-2018-20882MEDIUMCVSS 6.8EG 6.82019-08-01
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
- CVE-2018-20883MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
- CVE-2018-20891MEDIUMCVSS 5.5EG 5.52019-08-01
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
- CVE-2018-20893LOWCVSS 2.3EG 2.32019-08-01
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
- CVE-2018-20895HIGHCVSS 7.2EG 7.22019-08-01
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
- CVE-2018-20897LOWCVSS 2.8EG 2.82019-08-01
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
- CVE-2018-20912MEDIUMCVSS 6.3EG 6.32019-08-01
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
- CVE-2018-20917MEDIUMCVSS 5.5EG 5.52019-08-01
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
- CVE-2018-20973CRITICALCVSS 9.8EG 9.82019-08-16
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
- CVE-2018-20980HIGHCVSS 7.5EG 7.52019-08-22
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
- CVE-2018-20981CRITICALCVSS 9.1EG 9.12019-08-22
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
- CVE-2018-20985CRITICALCVSS 9.8EG 9.82019-08-22
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
- CVE-2018-21020HIGHCVSS 7.5EG 7.52019-10-08
In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.
- CVE-2018-21033MEDIUMCVSS 6.5EG 6.52020-02-14
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style …
- CVE-2018-21036HIGHCVSS 7.5EG 7.52020-07-21
Sails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error handler in sails-hook-sockets to handle an empty pathname in a WebSocket request.
- CVE-2018-21055CRITICALCVSS 9.8EG 9.82020-04-08
An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software. A device can be rooted with a custom image to execute arbitrary scripts in the INIT context. The Samsung ID is SVE-2018-11940 …
- CVE-2018-21068MEDIUMCVSS 6.2EG 6.22020-04-08
An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a password via a split screen. The Samsung ID is SVE-2018-11669 (July 2018).
- CVE-2018-21078HIGHCVSS 7.5EG 7.52020-04-08
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate video calls because SS (Supplementary Service) and USSD (Unstructured Supplementary Service …
- CVE-2018-21092MEDIUMCVSS 6.5EG 6.52020-04-08
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via an NFC tag. The Samsung ID is SVE-2017-10885 (January 2018).
- CVE-2018-21115HIGHCVSS 8.8EG 8.82020-04-22
NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers.
- CVE-2018-21122MEDIUMCVSS 6.5EG 6.52020-04-22
Certain NETGEAR devices are affected by denial of service. This affects GS110EMX before 1.0.0.9, GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6.
- CVE-2018-21140MEDIUMCVSS 6.5EG 6.52020-04-21
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.
- CVE-2018-21141MEDIUMCVSS 4.5EG 4.52020-04-21
Certain NETGEAR devices are affected by denial of service. This affects R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.9…
- CVE-2018-21259MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.
- CVE-2018-21262HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.
- CVE-2018-21264HIGHCVSS 8.8EG 8.82020-06-19
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
- CVE-2018-2416MEDIUMCVSS 5.4EG 5.42018-05-09
SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
- CVE-2018-2424CRITICALCVSS 9.8EG 7.52018-06-12
SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Databa…
- CVE-2018-2439MEDIUMCVSS 5.9EG 5.92018-07-10
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid req…
- CVE-2018-2462HIGHCVSS 8.8EG 8.82018-09-11
In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.
- CVE-2018-2465HIGHCVSS 7.5EG 7.52018-09-11
SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash.
- CVE-2018-25002HIGHCVSS 8.8EG 8.82021-01-01
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.
- CVE-2018-25004MEDIUMCVSS 4.9EG 4.92021-03-01
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions …
- CVE-2018-25031MEDIUMCVSS 4.3EG 4.32022-03-11
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was origin…
- CVE-2018-3574MEDIUMCVSS 5.5EG 5.52018-09-19
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, userspace can request ION cache maintenance on a secure ION buffer for which the ION_FLAG_SECURE ion flag is not set and cause the …
- CVE-2018-3582HIGHCVSS 7.8EG 7.82018-06-12
Buffer overflow can occur due to improper input validation in multiple WMA event handler functions in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- CVE-2018-3597HIGHCVSS 7.8EG 7.82018-07-06
In the ADSP RPC driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, an arbitrary kernel write can occur.
- CVE-2018-3611MEDIUMCVSS 6.5EG 6.52018-05-15
Bounds check vulnerability in User Mode Driver in Intel Graphics Driver 15.40.x.4 and 21.20.x.x allows unprivileged user to cause a denial of service via local access.
- CVE-2018-3612HIGHCVSS 7.8EG 7.82018-05-10
Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).
Map vulnerabilities like CWE-20 to your infrastructure
EchelonGraph correlates every CVE — across CWE-20 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →