← Back
CWE-20

12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,949)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
1Quickassist Technology
Jun 17, 2026
Nov 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.
1Amd
5Radeon Pro Vega 56 Firmware
Radeon Pro Vega 64 FirmwareRadeon Rx Vega 56 Firmware+2 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.
1Intel
1Openvino Model Server
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network acce...Show more
Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access.Show less
1Intel
5Optane Memory H20 With Solid State Storage Firmware
Optane Ssd 900p FirmwareOptane Ssd 905p Firmware+2 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Unison Software
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
1Intel
629Atom X6200fe Firmware
Atom X6211e FirmwareAtom X6212re Firmware+626 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
3.5 LOW· v3
N/A· v2
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
1Intel
1Unison Software
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
33Compute Module Hns2600bpb24 Firmware
Compute Module Hns2600bpb FirmwareCompute Module Hns2600bpblc24 Firmware+30 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
2Server Board M70klp2sb Firmware
Server System M70klp4s2uhh Firmware
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow a privileged user to potentially enable escalation of privilege via local access.
1Amd
105Athlon 3015ce Firmware
Athlon 3015e FirmwareRyzen 3 3100 Firmware+102 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability
1Microsoft
5Windows 11 21h2
Windows 11 22h2Windows 11 23h2+2 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Hyper-V Elevation of Privilege Vulnerability
1Microsoft
5Windows 11 21h2
Windows 11 22h2Windows 11 23h2+2 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Hyper-V Information Disclosure Vulnerability
1Microsoft
1On Prem Data Gateway
Jun 17, 2026
Nov 14, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability
1Volkswagen
1Id.3 Firmware
Jun 17, 2026
Nov 10, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio...Show more
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls. Show less
1Ibm
2Aix
Vios
Jun 17, 2026
Nov 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965.
1Lenovo
1Lecloud
Jun 17, 2026
Nov 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could result in information disclosure.
1Lenovo
111Ideacentre 3 07ada05 Firmware
Ideacentre 3 07imb05 FirmwareIdeacentre 5 14acn6 Firmware+108 more
Jun 17, 2026
Nov 8, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.
1Thm
1Pilos
Jun 17, 2026
Nov 8, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a pass...Show more
PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to PILOS users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. This only affects local user accounts and requires the password reset option to be enabled. This issue has been patched in version 2.3.0.Show less
1Lanaccess
1Onsafe Monitorhm
Jun 17, 2026
Nov 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code exe...Show more
An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.Show less