← Back
CWE-20

12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,961)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Defender For Endpoint
Aug 10, 2026
Feb 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
1Microsoft
8Windows 10 1809
Windows 10 21h2Windows 10 22h2+5 more
Aug 10, 2026
Feb 13, 2024
N/A· v4
4.1 MEDIUM· v3
N/A· v2
Trusted Compute Base Elevation of Privilege Vulnerability
1Microsoft
5Windows 11 21h2
Windows 11 22h2Windows 11 23h2+2 more
Aug 10, 2026
Feb 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows Hyper-V Denial of Service Vulnerability
1Envoyproxy
1Envoy
Jun 17, 2026
Feb 9, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_auth...Show more
Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Feb 9, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when...Show more
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to the execution of the malicious code on the website user’s browser. The Concrete CMS Security team scored this 2 with CVSS v3 vector AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N. This does not affect Concrete versions prior to version 9. Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Feb 9, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue admi...Show more
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious code into the file tags or description attributes and, when another administrator opens the same file for editing, the malicious code could execute. The Concrete CMS Security team scored this 2.4 with CVSS v3 vector AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N. Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Feb 9, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious...Show more
Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed when users visit the affected page. The Concrete CMS Security team scored this 2 with CVSS v3 vector AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Concrete versions below 9 do not include group types so they are not affected by this vulnerability. Show less
1Zabbix
1Zabbix
Jun 17, 2026
Feb 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
1Tenable
1Nessus
Jun 17, 2026
Feb 7, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary...Show more
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts. Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
1Qualcomm
95315 5g Iot Modem Firmware
Ar8035 FirmwareFastconnect 6200 Firmware+92 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in Multi-Mode Call Processor while processing UE policy container.
1Eyuepcanyilmaz
1Root Quick Reboot
Jun 17, 2026
Feb 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff...Show more
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.Show less
1Mediatek
1Nr15
Jun 17, 2026
Feb 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges...Show more
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01195812 (MSV-985).Show less
1Mediatek
1Nr15
Jun 17, 2026
Feb 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges...Show more
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01191612 (MSV-981).Show less
1Openatom
1Openharmony
Jun 17, 2026
Feb 2, 2024
N/A· v4
6.2 MEDIUM· v3
N/A· v2
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
1Openatom
1Openharmony
Jun 17, 2026
Feb 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
1Ibm
1Storage Ceph
Jun 17, 2026
Feb 2, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906.
1Machinesense
1Feverwarn Firmware
Jun 17, 2026
Feb 1, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.
1Microsoft
1Edge Chromium
Jun 17, 2026
Jan 30, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
1Owasp
1Modsecurity
Jun 17, 2026
Jan 30, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs bef...Show more
ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators and users are advised to upgrade to 3.0.12. The ModSecurity v2 release line is not affected by this vulnerability.Show less