← Back
CWE-20

12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,949)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Apache Airflow Providers Apache Hive
Jun 17, 2026
Jul 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass th...Show more
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this to be exploited it requires access to modifying the connection details. It is recommended updating provider version to 6.1.1 in order to avoid this vulnerability.Show less
1Ivanti
1Endpoint Manager
Jun 17, 2026
Jul 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
1Apache
1Apache Airflow Providers Jdbc
Jun 17, 2026
Jun 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement...Show more
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects Apache Airflow JDBC Provider: before 4.0.0. Show less
1Google
1Android
Jun 17, 2026
Jun 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privile...Show more
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227207653Show less
1Cisco
1Telepresence Video Communication Server
Jun 17, 2026
Jun 28, 2023
N/A· v4
7.7 HIGH· v3
N/A· v2
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges...Show more
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Telepresence Video Communication Server
Jun 17, 2026
Jun 28, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate...Show more
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by authenticating to the application as a Read-only user and sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative user, and then impersonate that user. Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device.Show less
1Bund
1Bkg Professional Ntripcaster
Jun 17, 2026
Jun 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jun 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134.
1Apache
2Apache Airflow Providers Microsoft Mssql
Apache Airflow Providers Odbc
Jun 17, 2026
Jun 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `...Show more
Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone with access to connection resources specifically updating the connection to exploit it. This issue affects Apache Airflow ODBC Provider: before 4.0.0; Apache Airflow MSSQL Provider: before 3.4.1. It is recommended to upgrade to a version that is not affected Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
1Gobalsky
1Vega
Jun 17, 2026
Jun 23, 2023
N/A· v4
5.2 MEDIUM· v3
N/A· v2
Vega is a decentralized trading platform that allows pseudo-anonymous trading of derivatives on a blockchain. Prior to version 0.71.6, a vulnerability exists that allows a malicious validator to trick the Vega network in...Show more
Vega is a decentralized trading platform that allows pseudo-anonymous trading of derivatives on a blockchain. Prior to version 0.71.6, a vulnerability exists that allows a malicious validator to trick the Vega network into re-processing past Ethereum events from Vega’s Ethereum bridge. For example, a deposit to the collateral bridge for 100USDT that credits a party’s general account on Vega, can be re-processed 50 times resulting in 5000USDT in that party’s general account. This is without depositing any more than the original 100USDT on the bridge. Despite this exploit requiring access to a validator's Vega key, a validator key can be obtained at the small cost of 3000VEGA, the amount needed to announce a new node onto the network. A patch is available in version 0.71.6. No known workarounds are available, however there are mitigations in place should this vulnerability be exploited. There are monitoring alerts for `mainnet1` in place to identify any issues of this nature including this vulnerability being exploited. The validators have the ability to stop the bridge thus stopping any withdrawals should this vulnerability be exploited.Show less
1Nvidia
1Jetson Linux
Jun 17, 2026
Jun 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
NVIDIA Jetson Linux Driver Package contains a vulnerability in nvbootctrl, where a privileged local attacker can configure invalid settings, resulting in denial of service.
1Dell
31Alienware M15 R7 Firmware
G15 5510 FirmwareG15 5520 Firmware+28 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.
1Dell
434Alienware Area 51m R1 Firmware
Alienware Area 51m R2 FirmwareAlienware Aurora R11 Firmware+431 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
1Dell
434Alienware Area 51m R1 Firmware
Alienware Area 51m R2 FirmwareAlienware Aurora R11 Firmware+431 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
1Dell
434Alienware Area 51m R1 Firmware
Alienware Area 51m R2 FirmwareAlienware Aurora R11 Firmware+431 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
1Dell
434Alienware Area 51m R1 Firmware
Alienware Area 51m R2 FirmwareAlienware Aurora R11 Firmware+431 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
1Dell
434Alienware Area 51m R1 Firmware
Alienware Area 51m R2 FirmwareAlienware Aurora R11 Firmware+431 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
1Dell
434Alienware Area 51m R1 Firmware
Alienware Area 51m R2 FirmwareAlienware Aurora R11 Firmware+431 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.