← Back
CWE-20

12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,961)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rockwellautomation
15015 U8ihft Firmware
Jun 17, 2026
Sep 12, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable f...Show more
CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.Show less
1Cisco
1Ios Xr
Jun 17, 2026
Sep 11, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (...Show more
A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending specific IS-IS packets to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the IS-IS process on all affected devices that are participating in the Flexible Algorithm to crash and restart, resulting in a DoS condition. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device and must have formed an adjacency. This vulnerability affects segment routing for IS-IS over IPv4 and IPv6 control planes as well as devices that are configured as level 1, level 2, or multi-level routing IS-IS type.Show less
1Microsoft
6Windows Server 2008
Windows Server 2012Windows Server 2016+3 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Windows Remote Desktop Licensing Service Spoofing Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows Networking Denial of Service Vulnerability
1Microsoft
4Windows Server 2012
Windows Server 2016Windows Server 2019+1 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
1Microsoft
1Azure Stack Hub
Aug 10, 2026
Sep 10, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Azure Stack Hub Elevation of Privilege Vulnerability
1Microsoft
1Azure Web Apps
Aug 10, 2026
Sep 10, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
PowerShell Elevation of Privilege Vulnerability
1Microsoft
4Sql Server 2016
Sql Server 2017Sql Server 2019+1 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft SQL Server Elevation of Privilege Vulnerability
1Dell
27920 Xl Rack Firmware
Precision 7920 Rack Firmware
Jun 17, 2026
Sep 10, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Inf...Show more
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.Show less
1Samsung
9Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+6 more
Jun 17, 2026
Sep 9, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_sc...Show more
An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_scan_done_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.Show less
-
-
Jun 17, 2026
Sep 5, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
-
-
Jun 17, 2026
Sep 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 4, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.