← Back
CWE-20

12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,949)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
Jun 17, 2026
Sep 12, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Office Security Feature Bypass Vulnerability
1Microsoft
5365 Apps
OfficeOffice Long Term Servicing Channel+2 more
Jun 17, 2026
Sep 12, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Microsoft Word Remote Code Execution Vulnerability
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
Sep 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Word Information Disclosure Vulnerability
1Microsoft
1Azure Kubernetes Service
Jun 17, 2026
Sep 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
1Rockwellautomation
1Factorytalk View
Jun 17, 2026
Sep 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The dev...Show more
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function. Show less
1Adobe
2Commerce
Magento Open Source
Jun 17, 2026
Sep 12, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a pos...Show more
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.Show less
1Symfony
1Ux Autocomplete
Jun 17, 2026
Sep 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The pro...Show more
ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.Show less
1Tolgee
1Tolgee
Jun 17, 2026
Sep 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from...Show more
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML ends up in invitation emails which appear as legitimate org invitations. Bad actors may direct users to malicious website or execute javascript in the context of the users browser. This vulnerability has been addressed in version 3.29.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Apple
3Ipados
Iphone OsWatchos
Jun 17, 2026
Sep 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a repor...Show more
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.Show less
1Apache
1Superset
Jun 17, 2026
Sep 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected f...Show more
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Additionally, if Apache Superset is using a SQLite database for its metadata (not advised for production use) it could result in more severe vulnerabilities related to confidentiality and integrity. This vulnerability exists in Apache Superset versions up to and including 2.1.0.Show less
1Magento
1Magento
Jun 17, 2026
Sep 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with...Show more
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution on the system. Show less
1Samsung
1Android
Jun 17, 2026
Sep 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.
2Cacti
Fedoraproject
2Cacti
Fedora
Jun 17, 2026
Sep 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many f...Show more
Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not perform prior validation of user input, leading to the existence of multiple SQL injection vulnerabilities in Cacti. This allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
2Arubanetworks
Hp
2Airwave
Airwave
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.
1Openautomationsoftware
1Oas Platform
Jun 17, 2026
Sep 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected...Show more
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Apache
1Axis
Jun 17, 2026
Sep 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanism...Show more
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE. As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does not expect to create an Axis 1.x release fixing this problem, though contributors that would like to work towards this are welcome.Show less
1Ibm
1Security Guardium
Jun 17, 2026
Sep 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
3Google
LinuxfoundationMediatek
3Android
Iot YoctoYocto
Jun 17, 2026
Sep 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n...Show more
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.Show less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosure no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In vdsp device, there is a possible system crash due to improper input validation.This could lead to local denial of service with System execution privileges needed