CWE-20
12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,973)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the aDBc_prepare_element...Show more |
Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input...Show more |
1Devolutions 1Devolutions Server Jun 17, 2026 Oct 22, 2025 5.1 MEDIUM· v4 4.1 MEDIUM· v3 N/A· v2 An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a crafted req...Show more |
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the ltq-ptm driver which is used to drive the...Show more |
1Azure Access 2Blu Ic2 Firmware Blu Ic4 FirmwareJun 17, 2026 Oct 20, 2025 10.0 CRITICAL· v4 6.1 MEDIUM· v3 N/A· v2 Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
1Samsung 13Exynos 1080 Firmware Exynos 1330 FirmwareExynos 1380 Firmware+10 moreJun 17, 2026 Oct 20, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 9110, W920, W930, Modem 5123, and Modem 5300. Incorrect handling of...Show more |
A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserializat...Show more |
Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain conditions, this could lead to arbitrary...Show more |
Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute arbitrary code via supplying crafted data. |
1Microsoft 1Jdbc Driver For Sql Server Jun 17, 2026 Oct 14, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Oct 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
1Microsoft 11Windows 10 1809 Windows 10 21h2Windows 10 22h2+8 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 5.0 MEDIUM· v3 N/A· v2 Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Oct 14, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
1Microsoft 11Windows 10 1809 Windows 10 21h2Windows 10 22h2+8 moreJun 17, 2026 Oct 14, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. |
A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service. |