CWE-20
12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,961)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot. |
NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead...Show more |
NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might l...Show more |
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthoriz...Show more |
A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM i...Show more |
Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to poten...Show more |
1Cisco 1Telepresence Management Suite Jun 17, 2026 Apr 3, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interf...Show more |
1Openautomationsoftware 1Open Automation Software Jun 17, 2026 Apr 3, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to unexpe...Show more |
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813...Show more |
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query. IBM X-Force ID: 282953. |
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables. IBM X-Force ID: 280905. |
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently. IBM X-Force ID: 278547. |
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input. |
in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input. |
1Qualcomm 127Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+124 moreJun 17, 2026 Apr 1, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption while redirecting log file to any file location with any file name. |
1Qualcomm 13C V2x 9150 Firmware Qcs410 FirmwareQcs610 Firmware+10 moreJun 17, 2026 Apr 1, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while decoding message of size that exceeds the available system memory. |
1Qualcomm 6C V2x 9150 Firmware Qca6584au FirmwareQca6698aq Firmware+3 moreJun 17, 2026 Apr 1, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions. |
1Qualcomm 48Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+45 moreJun 17, 2026 Apr 1, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification. |
1Qualcomm 97315 5g Iot Modem Firmware Ar8035 FirmwareFastconnect 6200 Firmware+94 moreJun 17, 2026 Apr 1, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR. |
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerab...Show more |