CWE-20
12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,973)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Opensourcepos 1Open Source Point Of Sale Jun 17, 2026 Dec 17, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter. |
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system c...Show more |
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call `install.php` and perform various adminis...Show more |
The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is due to the plugin not properly validating the 'role' parameter when cre...Show more |
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that ca...Show more |
A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the function pickle.loads of the file pickle_convert.go of the component Pickle Decoding. The manipulation le...Show more |
A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, w...Show more |
The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to cause a denial-of-service. |
A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.1. Visiting a website may lead to an app denial-of-service. |
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the prompts via PATCH endpoint for prompt groups (/api/prompts/groups...Show more |
In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional executio...Show more |
In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User...Show more |
1Hashenudara 1Edoc Doctor Appointment System Jun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter. |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Act...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers w...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated at...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authe...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attack...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers...Show more |