CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed |
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed |
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed |
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code. |
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users. |
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Window...Show more |
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Window...Show more |
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is...Show more |
1Lenovo 54Thinkpad L14 Firmware Thinkpad L14 Gen 2 FirmwareThinkpad L15 Firmware+51 moreJun 17, 2026 Oct 30, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
|
1Lenovo 1Thinkpad X1 Fold Gen 1 Firmware Jun 17, 2026 Oct 30, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2
An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.
|
1Lenovo 85Thinkpad E14 Firmware Thinkpad E14 Gen 2 FirmwareThinkpad E14 Gen 4 Firmware+82 moreJun 17, 2026 Oct 30, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. |
Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. |
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine us...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Oct 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would bec...Show more |
1Lenovo 3G263dns Firmware Gm265dn FirmwareGm266dns FirmwareJun 17, 2026 Oct 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents...Show more |
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.
|
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. |
Ingress nginx annotation injection causes arbitrary command execution. |
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. |
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYS...Show more |