CWE-20
12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,961)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address. |
Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access. |
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma p...Show more |
A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network processor to reset, resulting in a denial of service (DoS) condit...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraTomcatJun 17, 2026 Mar 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated H...Show more |
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId parameter in all versions up to, and including, 4.5.1 due to in...Show more |
1Dell 86Dss 8440 Firmware Emc Storage Nx3240 FirmwareEmc Storage Nx3340 Firmware+83 moreJun 17, 2026 Mar 13, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arb...Show more |
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "ht...Show more |
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided fu...Show more |
1Microsoft 4Windows Server 2012 Windows Server 2016Windows Server 2019+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Mar 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Kernel Denial of Service Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Microsoft 7Windows 10 21h2 Windows 10 22h2Windows 11 21h2+4 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability |
Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability |
Microsoft Teams for Android Information Disclosure Vulnerability |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
|
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation. |
In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with n...Show more |