← Back
CWE-20

12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,973)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Aug 18, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.
1Hcltech
1Bigfix Saas
Jun 17, 2026
Aug 15, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
-
-
Jun 17, 2026
Aug 15, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash...Show more
A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.Show less
-
-
Jun 17, 2026
Aug 15, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to, and including, 1.1.0. This is due to the plugin not restricting URLS that can be supplied through the elink shortc...Show more
The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to, and including, 1.1.0. This is due to the plugin not restricting URLS that can be supplied through the elink shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to supply an HTML file that can be leverged to redirect users to a malicious domain.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Aug 14, 2025
N/A· v4
8.5 HIGH· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated docum...Show more
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by submitting malicious content to an affected device and using the device to generate a document that contains sensitive information. A successful exploit could allow the attacker to alter the standard layout of the device-generated documents, read arbitrary files from the underlying operating system, and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (Read Only).Show less
1N Able
1N Central
Jun 17, 2026
Aug 14, 2025
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
-
-
Jun 17, 2026
Aug 14, 2025
7.3 HIGH· v4
N/A· v3
N/A· v2
A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the specified path lacks a valid file, Logix Designer crashes; However, it may be possible to execute malicio...Show more
A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the specified path lacks a valid file, Logix Designer crashes; However, it may be possible to execute malicious code without triggering a crash.Show less
1Jeecg
1Jimureport
Jun 17, 2026
Aug 14, 2025
5.3 MEDIUM· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The...Show more
A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".Show less
-
-
Jun 17, 2026
Aug 14, 2025
8.3 HIGH· v4
N/A· v3
N/A· v2
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
-
-
Jun 17, 2026
Aug 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.
-
-
Jun 17, 2026
Aug 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
-
-
Jun 17, 2026
Aug 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
1Adobe
3Commerce
Commerce B2bMagento
Jun 17, 2026
Aug 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attack...Show more
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing the application to crash or become unresponsive. Exploitation of this issue does not require user interaction.Show less
1Microsoft
2Exchange Server
Exchange Server Subscription Edition
Jun 17, 2026
Aug 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
-
-
Jun 17, 2026
Aug 12, 2025
1.8 LOW· v4
3.9 LOW· v3
N/A· v2
Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Aug 12, 2025
5.1 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
-
-
Jun 17, 2026
Aug 12, 2025
8.8 HIGH· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Aug 12, 2025
8.8 HIGH· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Aug 12, 2025
9.3 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Aug 12, 2025
5.1 MEDIUM· v4
6.0 MEDIUM· v3
N/A· v2
Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial of service via local access.