← Back
CWE-20

12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,961)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Aug 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service which may result in service degradation.
-
-
Jun 17, 2026
Aug 16, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary comman...Show more
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.Show less
-
-
Jun 17, 2026
Aug 16, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privile...Show more
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user having the system administrator role to exploit the vulnerability.Show less
1J4k0xb
1Webcrack
Jun 17, 2026
Aug 15, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is tri...Show more
webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles feature in conjunction with the saving feature. If a module name includes a path traversal sequence with Windows path separators, an attacker can exploit this to overwrite files on the host system. This vulnerability allows an attacker to write arbitrary `.js` files to the host system, which can be leveraged to hijack legitimate Node.js modules to gain arbitrary code execution. This vulnerability has been patched in version 2.14.1.Show less
1Rockwellautomation
6Compact Guardlogix 5380 Sil 2 Firmware
Compact Guardlogix 5380 Sil 3 FirmwareCompactlogix 5380 Firmware+3 more
Jun 17, 2026
Aug 14, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.
1Rockwellautomation
6Compact Guardlogix 5380 Sil 2 Firmware
Compact Guardlogix 5380 Sil 3 FirmwareCompactlogix 5380 Firmware+3 more
Jun 17, 2026
Aug 14, 2024
8.7 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.
1Adobe
1Illustrator
Jun 17, 2026
Aug 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of thi...Show more
Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Illustrator
Jun 17, 2026
Aug 14, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service condition. An attacker could exploit this vulnerability to rend...Show more
Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service condition. An attacker could exploit this vulnerability to render the application unresponsive or terminate its execution. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Intel
9Nuc X15 Laptop Kit Lapac71g Firmware
Nuc X15 Laptop Kit Lapac71h FirmwareNuc X15 Laptop Kit Lapbc510 Firmware+6 more
Jun 17, 2026
Aug 14, 2024
8.7 HIGH· v4
8.2 HIGH· v3
N/A· v2
Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access.
1Intel
1Server Board S2600st Firmware
Jun 17, 2026
Aug 14, 2024
7.1 HIGH· v4
8.2 HIGH· v3
N/A· v2
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
2Distribution For Gdb
Oneapi Base Toolkit
Jun 17, 2026
Aug 14, 2024
1.0 LOW· v4
3.3 LOW· v3
N/A· v2
Improper input validation for some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.
-
-
Jun 17, 2026
Aug 14, 2024
9.3 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via...Show more
Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
-
-
Jun 17, 2026
Aug 14, 2024
6.7 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
Improper input validation in firmware for some Intel(R) CSME may allow a privileged user to potentially enable denial of service via local access.
1Dell
41Embedded Box Pc 5000 Firmware
Latitude 12 Rugged Extreme 7214 FirmwareLatitude 13 3380 Firmware+38 more
Jun 17, 2026
Aug 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
1Ivanti
1Avalanche
Jun 17, 2026
Aug 14, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
1Microsoft
1Azure Stack Hub
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
Azure Stack Hub Elevation of Privilege Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Microsoft
4365 Apps
Office 2019Office Long Term Servicing Channel+1 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft Project Remote Code Execution Vulnerability
1Amd
1Uprof
Jun 17, 2026
Aug 13, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.
3Amd
ArmTrustedfirmware
3Trusted Firmware A
Trusted Firmware ATrusted Firmware A
Jun 17, 2026
Aug 13, 2024
N/A· v4
5.8 MEDIUM· v3
N/A· v2
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.