CWE-20
12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,961)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 1809 Windows 10 21h2Windows 10 22h2+5 moreAug 10, 2026 Feb 13, 2024 N/A· v4 4.1 MEDIUM· v3 N/A· v2 Trusted Compute Base Elevation of Privilege Vulnerability |
1Microsoft 5Windows 11 21h2 Windows 11 22h2Windows 11 23h2+2 moreAug 10, 2026 Feb 13, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows Hyper-V Denial of Service Vulnerability |
Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_auth...Show more |
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when...Show more |
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue admi...Show more |
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious...Show more |
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. |
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary...Show more |
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL |
1Qualcomm 95315 5g Iot Modem Firmware Ar8035 FirmwareFastconnect 6200 Firmware+92 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in Multi-Mode Call Processor while processing UE policy container. |
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff...Show more |
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges...Show more |
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges...Show more |
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input. |
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input. |
IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906. |
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.
|
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs bef...Show more |