CWE-20
12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,973)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgr...Show more |
Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lead to remote code execution within Volt components. This vulnerability is fixed in 1.7.0. |
The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.4.0 via deserialization of untrusted input from the 'raccookie_guest_email' cooki...Show more |
2Debian Libreoffice2Debian Linux LibreofficeJun 17, 2026 Mar 4, 2025 7.2 HIGH· v4 7.8 HIGH· v3 N/A· v2 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions o...Show more |
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with Contr...Show more |
Permission verification bypass vulnerability in the notification module
Impact: Successful exploitation of this vulnerability may affect availability. |
1Qualcomm 26Qam8255p Firmware Qam8295p FirmwareQam8620p Firmware+23 moreJun 17, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine. |
1Qualcomm 44Msm8996au Firmware Qam8255p FirmwareQam8295p Firmware+41 moreJun 17, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing input message passed from FE driver. |
1Qualcomm 26Qam8255p Firmware Qam8295p FirmwareQam8620p Firmware+23 moreJun 17, 2026 Mar 3, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine. |
1Qualcomm 23Qam8255p Firmware Qam8295p FirmwareQam8620p Firmware+20 moreJun 17, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur during communication between primary and guest VM. |
1Qualcomm 26Qam8255p Firmware Qam8295p FirmwareQam8620p Firmware+23 moreJun 17, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur due to improper input validation in clock device. |
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it pos...Show more |
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation. |
A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this vulnerability is an unknown functionality of the file src/admin/users.php of the component Admin Page. The manipulation of...Show more |
Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before <...Show more |
1Westboy 1Cicadascms Jun 17, 2026 Feb 22, 2025 5.1 MEDIUM· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Template Management. The manipulation leads...Show more |
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. Thi...Show more |
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored c...Show more |
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for auth...Show more |
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for...Show more |