CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreAug 10, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
1Microsoft 12Windows 10 Windows 10 1607Windows 10 1809+9 moreAug 10, 2026 Aug 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
1Microsoft 7365 Apps OfficeOffice Long Term Servicing Channel+4 moreAug 10, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Visual Studio Tools for Office Runtime Spoofing Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreAug 10, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Outlook Spoofing Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreAug 10, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreAug 10, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
Microsoft Exchange Remote Code Execution Vulnerability |
SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior t...Show more |
1Qualcomm 43Qca6390 Firmware Qca6391 FirmwareQca6426 Firmware+40 moreJun 17, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Information disclosure in Bluetooth when an GATT packet is received due to improper input validation. |
1Qualcomm 48Aqt1000 Firmware Qca6390 FirmwareQca6391 Firmware+45 moreJun 17, 2026 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Trusted Execution Environment while calling service API with invalid address. |
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no kno...Show more |
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachments controller and the Attachments API. Version 8.1.1 contains a patch...Show more |
import-in-the-middle is a module loading interceptor specifically for ESM modules. The import-in-the-middle loader works by generating a wrapper module on the fly. The wrapper uses the module specifier to load the origin...Show more |
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM...Show more |
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affec...Show more |
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as...Show more |
A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 . |
1Codesys 16Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+13 moreJun 17, 2026 Aug 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internall...Show more |
1Codesys 16Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+13 moreJun 17, 2026 Aug 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internall...Show more |
1Codesys 16Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+13 moreJun 17, 2026 Aug 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally...Show more |