CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dell 434Alienware Area 51m R1 Firmware Alienware Area 51m R2 FirmwareAlienware Aurora R11 Firmware+431 moreJun 17, 2026 Jun 23, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
|
1Dell 45Vxrail D560 Firmware Vxrail D560f FirmwareVxrail E460 Firmware+42 moreJun 17, 2026 Jun 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to degraded per...Show more |
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When...Show more |
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An admin privilege...Show more |
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. Us...Show more |
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User e...Show more |
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. Use...Show more |
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional executio...Show more |
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no ad...Show more |
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Jun 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocke...Show more |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Jun 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows CryptoAPI Denial of Service Vulnerability |
.NET and Visual Studio Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jun 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows GDI Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 GDI Elevation of Privilege Vulnerability |
1Microsoft 2Sysinternals Sysinternals Process MonitorJun 17, 2026 Jun 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Sysinternals Process Monitor for Windows Denial of Service Vulnerability |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreJun 17, 2026 Jun 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role...Show more |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreJun 17, 2026 Jun 9, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code. |
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for auth...Show more |