CWE-20
12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,961)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of administrative users and deletion or modification of data in the applicatio...Show more |
1Rockwellautomation 2Thinmanager ThinserverJun 17, 2026 Jun 25, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device. |
1Rockwellautomation 2Thinmanager ThinserverJun 17, 2026 Jun 25, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManage...Show more |
1Rockwellautomation 2Thinmanager ThinserverJun 17, 2026 Jun 25, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager®...Show more |
This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality. By injecting PHP code into the database, an attacker with a...Show more |
2Freedesktop Redhat2Enterprise Linux PopplerJun 17, 2026 Jun 21, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a de...Show more |
The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The iss...Show more |
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements...Show more |
Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql c...Show more |
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js proces...Show more |
The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to insufficient limitations on the email recipient and the conten...Show more |
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...Show more |
Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file. |
In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...Show more |
In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed....Show more |
1Dell 22Alienware Area 51m R2 Firmware Alienware Aurora R11 FirmwareAlienware Aurora R12 Firmware+19 moreJun 17, 2026 Jun 13, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Co...Show more |
1Dell 23Alienware Area 51m R2 Firmware Alienware Aurora R10 FirmwareAlienware Aurora R11 Firmware+20 moreJun 17, 2026 Jun 13, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Co...Show more |
1Dell 23Alienware Area 51m R2 Firmware Alienware Aurora R10 FirmwareAlienware Aurora R11 Firmware+20 moreJun 17, 2026 Jun 13, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Co...Show more |
1Dell 23Alienware Area 51m R2 Firmware Alienware Aurora R10 FirmwareAlienware Aurora R11 Firmware+20 moreJun 17, 2026 Jun 13, 2024 N/A· v4 6.0 MEDIUM· v3 N/A· v2 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to In...Show more |
1Adobe 3Commerce Commerce WebhooksMagentoJun 17, 2026 Jun 13, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploit...Show more |