CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...Show more |
1Codesys 17Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+14 moreJun 17, 2026 May 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which ca...Show more |
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of...Show more |
1Codesys 17Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+14 moreJun 17, 2026 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service. |
1Codesys 17Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+14 moreJun 17, 2026 May 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-servic...Show more |
1Codesys 14Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+11 moreJun 17, 2026 May 15, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type. |
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerabili...Show more |
IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-...Show more |
An attacker who has gained access to an admin account can perform RCE via null-byte injection
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 |
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJun 17, 2026 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Pimcore 1Customer Management Framework Jun 17, 2026 May 11, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Co...Show more |
1Selinc 10Sel 2241 Rtac Module Firmware Sel 3350 FirmwareSel 3505 3 Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to arbitrarily alter the content...Show more |
1Selinc 5Sel 3350 Firmware Sel 3532 FirmwareSel 3555 Firmware+2 moreJun 17, 2026 May 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow an authenticated remote attacker to use internal resources, allow...Show more |
1Selinc 10Sel 2241 Rtac Module Firmware Sel 3350 FirmwareSel 3505 3 Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See...Show more |
1Selinc 10Sel 2241 Rtac Module Firmware Sel 3350 FirmwareSel 3505 3 Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See...Show more |
1Intel 10Server System D50tnp1mhcpac Firmware Server System D50tnp1mhcrac FirmwareServer System D50tnp1mhcrlc Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access. |
Improper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable denial of service via local access. |
1Intel 10Server System D50tnp1mhcpac Firmware Server System D50tnp1mhcrac FirmwareServer System D50tnp1mhcrlc Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access. |
1Intel 10Server System D50tnp1mhcpac Firmware Server System D50tnp1mhcrac FirmwareServer System D50tnp1mhcrlc Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access. |