← Back
CWE-20

12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,973)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Feb 18, 2025
5.1 MEDIUM· v4
N/A· v3
N/A· v2
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the ses...Show more
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement.Show less
-
-
Jun 17, 2026
Feb 18, 2025
5.3 MEDIUM· v4
N/A· v3
N/A· v2
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the...Show more
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.Show less
-
-
Jun 17, 2026
Feb 18, 2025
8.6 HIGH· v4
N/A· v3
N/A· v2
An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the application. (Remote Code Execution) For this, the user must be able to create "ScriptVars" with the t...Show more
An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the application. (Remote Code Execution) For this, the user must be able to create "ScriptVars" with the type „script" and preview them by, for example, creating a new "Info". By default, admin users have those permissions, but with the granular permission system, those permissions may be assigned to other users. An attacker is able to execute commands on the server running the "bestinformed Web" application if an account with the correct permissions was compromised before.Show less
1Watchguard
1Fireware
Aug 8, 2026
Feb 14, 2025
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this v...Show more
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.Show less
-
-
Jun 17, 2026
Feb 13, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious IPV6 packets are sent to the device.
-
-
Jun 17, 2026
Feb 13, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to the device.
-
-
Jun 17, 2026
Feb 13, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to the device. The core functionality...Show more
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to the device. The core functionality of the breaker remains intact during the attack.Show less
-
-
Jun 17, 2026
Feb 13, 2025
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
-
-
Jun 17, 2026
Feb 12, 2025
6.8 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
-
-
Jun 17, 2026
Feb 12, 2025
6.0 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
-
-
Jun 17, 2026
Feb 12, 2025
7.1 HIGH· v4
7.7 HIGH· v3
N/A· v2
Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access.
1Intel
1Quickassist Technology
Jun 17, 2026
Feb 12, 2025
5.1 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.
-
-
Jun 17, 2026
Feb 12, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
6.8 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
-
-
Jun 17, 2026
Feb 12, 2025
4.6 MEDIUM· v4
2.3 LOW· v3
N/A· v2
Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access.
-
-
Jun 17, 2026
Feb 12, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
8.7 HIGH· v4
8.2 HIGH· v3
N/A· v2
Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.