← Back
CWE-20

12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,949)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Nov 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
1Elenos
1Etg150 Firmware
Jun 17, 2026
Oct 31, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.
1Kubernetes
1Kubernetes
Jun 17, 2026
Oct 31, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Window...Show more
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.Show less
1Kubernetes
1Kubernetes
Jun 17, 2026
Oct 31, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Window...Show more
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.Show less
1Google
1Android
Jun 17, 2026
Oct 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is...Show more
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
1Lenovo
54Thinkpad L14 Firmware
Thinkpad L14 Gen 2 FirmwareThinkpad L15 Firmware+51 more
Jun 17, 2026
Oct 30, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  
1Lenovo
1Thinkpad X1 Fold Gen 1 Firmware
Jun 17, 2026
Oct 30, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.
1Lenovo
85Thinkpad E14 Firmware
Thinkpad E14 Gen 2 FirmwareThinkpad E14 Gen 4 Firmware+82 more
Jun 17, 2026
Oct 30, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
1Mintplexlabs
1Anythingllm
Jun 17, 2026
Oct 30, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
1Hallowelt
1Bluespice
Jun 17, 2026
Oct 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine us...Show more
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.Show less
1Rockwellautomation
1Factorytalk View
Jun 17, 2026
Oct 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would bec...Show more
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition. Show less
1Lenovo
3G263dns Firmware
Gm265dn FirmwareGm266dns Firmware
Jun 17, 2026
Oct 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents...Show more
A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.Show less
1Tenable
1Nessus Network Monitor
Jun 17, 2026
Oct 26, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Ingress nginx annotation injection causes arbitrary command execution.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
1Zscaler
1Client Connector
Jun 17, 2026
Oct 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYS...Show more
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges. Show less