CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum of the UTxO at the head validator must stay unchanged as the state prog...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Oct 4, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. T...Show more |
Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head first to the `commit` validator, where they remain until they are either co...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Oct 4, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instanc...Show more |
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. |
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities. |
JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body. |
1Qualcomm 111Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+108 moreJun 17, 2026 Oct 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption in HLOS while registering for key provisioning notify. |
1Qualcomm 29Apq8064au Firmware Msm8996au FirmwareQam8295p Firmware+26 moreJun 17, 2026 Oct 3, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Weak configuration in Automotive while VM is processing a listener request from TEE. |
Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the affected device is located to use the discovery port protocol (1925/UDP) to obtain device-specific in...Show more |
Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would cr...Show more |
1Ingeteam 3Ingepac Da3451 Firmware Ingepac Ef Md FirmwareIngepac Fc5066 FirmwareJun 17, 2026 Oct 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would cr...Show more |
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...Show more |
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...Show more |
4Google LinuxLinuxfoundation+1 more4Android Iot YoctoLinux Kernel+1 moreJun 17, 2026 Oct 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for expl...Show more |
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validatio...Show more |
Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out arbitrary files on the server |
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified. |
Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. |
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. |