← Back
CWE-20

12,731 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,731)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Shockwave Player
Apr 29, 2026
Feb 10, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The Shockwave 3d Asset module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
1Adobe
1Shockwave Player
Apr 29, 2026
Feb 10, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The TextXtra module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
1Adobe
1Shockwave Player
Apr 29, 2026
Feb 10, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
1Adobe
1Shockwave Player
Apr 29, 2026
Feb 10, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, a...Show more
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, as demonstrated by omni_chk_ds.sh.Show less
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by...Show more
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.Show less
1Microsoft
6Windows 2003 Server
Windows 7Windows Server 2003+3 more
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode inp...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."Show less
1Microsoft
6Windows 2003 Server
Windows 7Windows Server 2003+3 more
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode inp...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."Show less
1Microsoft
6Windows 2003 Server
Windows 7Windows Server 2003+3 more
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode inp...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."Show less
1Microsoft
5Windows 2003 Server
Windows Server 2003Windows Server 2008+2 more
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain pri...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."Show less
1Microsoft
6Windows 2003 Server
Windows 7Windows Server 2003+3 more
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode inp...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."Show less
1Microsoft
1Windows 2003 Server
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authenticatio...Show more
The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."Show less
1Ibm
1Lotus Notes
Apr 29, 2026
Feb 8, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifi...Show more
Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.Show less
1Vanillaforums
1Vanilla
Apr 29, 2026
Feb 8, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a...Show more
Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526.Show less
1Videolan
1Vlc Media Player
Apr 29, 2026
Feb 7, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska...Show more
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.Show less
1Redhat
1Icedtea
Apr 29, 2026
Feb 4, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to tric...Show more
IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.Show less
1Google
1Chrome
Apr 29, 2026
Feb 4, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 9.0.597.84 does not properly handle autofill profile merging, which has unspecified impact and remote attack vectors.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Feb 4, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafted extension.