CWE-20
12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,961)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service settings due to improper input validation. This could lead to local esca...Show more |
1Samsung 2Exynos 1380 Firmware Exynos 1480 FirmwareJun 17, 2026 Jul 9, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which...Show more |
1Samsung 2Exynos 1380 Firmware Exynos 1480 FirmwareJun 17, 2026 Jul 9, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which...Show more |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
.NET and Visual Studio Denial of Service Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Jul 9, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Microsoft Windows Codecs Library Information Disclosure Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 PowerShell Elevation of Privilege Vulnerability |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 PowerShell Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 PowerShell Elevation of Privilege Vulnerability |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft Outlook Remote Code Execution Vulnerability |
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an app...Show more |
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully crafted malicious URL can reduce the avai...Show more |
Under certain circumstances the web interface will accept characters unrelated to the expected input. |
Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement feature, enabling unauthorized...Show more |
1Dell 388Alienware M15 R6 Firmware Alienware M15 R7 FirmwareAlienware M16 R1 Firmware+385 moreJun 17, 2026 Jul 2, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service...Show more |
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2...Show more |
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior...Show more |
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. H...Show more |
HCL DRYiCE
AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which
can cause the system to behave in unexpected ways. |