← Back
CWE-20

12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,961)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Enterprise Sonic Distribution
Jun 17, 2026
Feb 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and es...Show more
Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level. This is a Critical vulnerability affecting certain protocols, Dell recommends customers to upgrade at the earliest opportunity. Show less
1Dell
1Smartfabric Os10
Jun 17, 2026
Feb 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerabilit...Show more
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system takeover. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity. Show less
1Tenable
1Security Center
Jun 17, 2026
Feb 14, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection at...Show more
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.Show less
1Intel
1Sgx Dcap
Jun 17, 2026
Feb 14, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenticateed user to potentially enable information disclosure via local access.
1Intel
2Killer
Proset/wireless
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1Intel
2Killer
Proset/wireless
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1Intel
2Killer
Proset/wireless
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Thunderbolt Dch Driver
Jun 17, 2026
Feb 14, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
1Intel
1Thunderbolt Dch Driver
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.7 HIGH· v3
N/A· v2
Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Zoom
3Meeting Software Development Kit
Vdi Windows Meeting ClientsZoom
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
1Zoom
3Meeting Software Development Kit
Vdi Windows Meeting ClientsZoom
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
1Github
1Enterprise Server
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when confi...Show more
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com . Show less
1Github
1Enterprise Server
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when confi...Show more
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com . Show less
1Github
1Enterprise Server
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings...Show more
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com . Show less
1Github
1Enterprise Server
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and...Show more
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com . Show less
1Github
1Enterprise Server
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy....Show more
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com . Show less
1Github
1Enterprise Server
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker...Show more
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program. Show less
1Github
1Enterprise Server
Jun 17, 2026
Feb 13, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configurat...Show more
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configuration file. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program. Show less
1Microsoft
4365 Apps
Office 2016Office 2019+1 more
Aug 10, 2026
Feb 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Outlook Remote Code Execution Vulnerability
1Microsoft
1Teams
Aug 10, 2026
Feb 13, 2024
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Microsoft Teams for Android Information Disclosure Vulnerability