CWE-20
12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,973)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authe...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbi...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted reque...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Dec 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to cause a denial of service (application crash) via a...Show more |
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write ma...Show more |
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue...Show more |
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass...Show more |
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Dec 9, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. |
1Microsoft 8Windows 10 1607 Windows 10 1809Windows 10 21h2+5 moreJun 17, 2026 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
1Netgear 18Mr90 Firmware Ms90 FirmwareRax35v2 Firmware+15 moreJun 17, 2026 Dec 9, 2025 4.4 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipul...Show more |
A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation.
This issue affects R7000P: through 1.3.3.154. |
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All v...Show more |
1Siemens 1Sinec Security Monitor Jun 17, 2026 Dec 9, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authentica...Show more |
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allow...Show more |
1Google 1Security Operations Soar Jun 17, 2026 Dec 9, 2025 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote Code Execution (RCE) in the server. The flaw stemmed from weak validati...Show more |
In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...Show more |
In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of pr...Show more |
In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...Show more |
In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...Show more |