CWE-20
12,961 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,961)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 268759. |
An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser.nim component. |
1Intel 2Nuc 8 Compute Element Cm8v5cb Firmware Nuc 8 Compute Element Cm8v7cb FirmwareJun 17, 2026 Jan 19, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 13Nuc 8 Enthusiast Nuc8i7behga Firmware Nuc 8 Enthusiast Nuc8i7bekqa FirmwareNuc 8 Home Nuc8i3behfa Firmware+10 moreJun 17, 2026 Jan 19, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 2Nuc 8 Mainstream G Kit Nuc8i5inh Firmware Nuc 8 Mainstream G Kit Nuc8i7inh FirmwareJun 17, 2026 Jan 19, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 4Nuc 9 Pro Compute Element Nuc9v7qnb Firmware Nuc 9 Pro Kit Nuc9v7qnb FirmwareNuc 9 Pro Kit Nuc9v7qnx Firmware+1 moreJun 17, 2026 Jan 19, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 6Nuc 7 Essential Nuc7cjysamn Firmware Nuc Kit Nuc7cjyh FirmwareNuc Kit Nuc7cjyhn Firmware+3 moreJun 17, 2026 Jan 19, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local access. |
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed |
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed |
In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a para...Show more |
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7. |
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of...Show more |
2Fedoraproject Rpm Software Management3Extra Packages For Enterprise Linux FedoraMockJun 17, 2026 Jan 16, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of p...Show more |
2Adobe Microsoft2Acrobat Edge ChromiumJun 17, 2026 Jan 15, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-...Show more |
2Adobe Microsoft2Acrobat Edge ChromiumJun 17, 2026 Jan 15, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-...Show more |
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead t...Show more |
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git ser...Show more |
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services. |
This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data thr...Show more |
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 2.10.26 due to insufficient input sanitization and output...Show more |