CWE-20
12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,973)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 144Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+141 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during the FRS UDS generation process. |
1Qualcomm 179Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+176 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while triggering commands in the PlayReady Trusted application. |
1Qualcomm 10Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSdm429w Firmware+7 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check. |
1Qualcomm 10Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSdm429w Firmware+7 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information. |
Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possi...Show more |
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulati...Show more |
Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An att...Show more |
1Microsoft 1Dynamics 365 Customer Service Jun 17, 2026 Apr 30, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. |
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be affected by this if all the following cond...Show more |
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information. |
Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to it...Show more |
An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecate...Show more |
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers...Show more |
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a w...Show more |
1Dell 2Elastic Cloud Storage ObjectscaleJun 17, 2026 Apr 17, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the function split_files/apply_delta_low_cpu_mem of the file fastchat/model/apply_delta.py. The manipulation le...Show more |
A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to...Show more |
A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization. The attack can be launched...Show more |
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments allows HTTP DoS.This issue affects Mediawiki - GrowthExperiments: from 1.39 through 1.43. |
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Extension:SimpleCalendar allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Extension:SimpleCalendar: from 1.39 through 1.43. |