CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Sep 12, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Microsoft Office Security Feature Bypass Vulnerability |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreJun 17, 2026 Sep 12, 2023 N/A· v4 7.3 HIGH· v3 N/A· v2 Microsoft Word Remote Code Execution Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 17, 2026 Sep 12, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Word Information Disclosure Vulnerability |
1Microsoft 1Azure Kubernetes Service Jun 17, 2026 Sep 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Sep 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The dev...Show more |
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a pos...Show more |
ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The pro...Show more |
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from...Show more |
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a repor...Show more |
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected f...Show more |
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with...Show more |
Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity. |
Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many f...Show more |
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS. |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 Sep 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected...Show more |
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanism...Show more |
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894. |
3Google LinuxfoundationMediatek3Android Iot YoctoYoctoJun 17, 2026 Sep 4, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n...Show more |
In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosure no additional execution privileges needed |
In vdsp device, there is a possible system crash due to improper input validation.This could lead to local denial of service with System execution privileges needed |