CWE-20
12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,961)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges nee...Show more |
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privil...Show more |
Numbas editor before 7.3 mishandles reading of themes and extensions. |
Numbas editor before 7.3 mishandles editing of themes and extensions. |
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution. |
4Apple FedoraprojectWebkitgtk+1 more10Fedora IpadosIphone Os+7 moreJun 17, 2026 Mar 8, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing malic...Show more |
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to bre...Show more |
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated us...Show more |
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 due to insufficient input sanitization and output es...Show more |
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would allow for creation of files outside of the allowed directories. This ma...Show more |
1Qualcomm 95315 5g Iot Modem Firmware Ar8035 FirmwareFastconnect 6200 Firmware+92 moreJun 17, 2026 Mar 4, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing PDU Release command with a parameter PDU ID out of range. |
1Qualcomm 47Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+44 moreJun 17, 2026 Mar 4, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing CAG info IE received from NW. |
1Qualcomm 333315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+330 moreJun 17, 2026 Mar 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Core Services while executing the command for removing a single event listener. |
In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more |
2Mediatek Openwrt2Openwrt Software Development KitJun 17, 2026 Mar 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for explo...Show more |
IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279. |
Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is prese...Show more |
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application d...Show more |
The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an attacker to execute arbitrary code.
|
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be...Show more |