CWE-20
12,958 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of service. IBM X-Force ID: 267971. |
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution. |
The issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be able to access sensitive user data. |
1Ptc 3Kepware Kepserverex Thingworx Industrial ConnectivityThingworx Kepware ServerJun 17, 2026 Jan 10, 2024 N/A· v4 4.7 MEDIUM· v3 N/A· v2 An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them...Show more |
There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.
|
1Microsoft 3.net Identity ModelVisual Studio 2022Jun 17, 2026 Jan 9, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Microsoft Identity Denial of service vulnerability |
1Microsoft 10Windows 10 1607 Windows 10 1809Windows 10 21h2+7 moreJun 17, 2026 Jan 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Windows Server Key Distribution Service Security Feature Bypass |
.NET Framework Denial of Service Vulnerability |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Jan 9, 2024 N/A· v4 6.6 MEDIUM· v3 N/A· v2 BitLocker Security Feature Bypass Vulnerability |
1Microsoft 4.net .net FrameworkPowershell+1 moreJun 17, 2026 Jan 9, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability |
In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of th...Show more |
1Microchip 1Maxview Storage Manager Jun 17, 2026 Jan 9, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SI...Show more |
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of...Show more |
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute sh...Show more |
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.
|
SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to trigger actions in the application from its web cont...Show more |
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based bu...Show more |
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta...Show more |
Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This...Show more |
An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application. |