← Back
CWE-20

12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,949)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...Show more
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which ca...Show more
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.Show less
1Apache
1Sling Commons Json
Jun 17, 2026
May 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of...Show more
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling Commons Johnzon OSGi bundle provided by the Apache Sling project, but may of course use other JSON libraries. Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-servic...Show more
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.Show less
1Codesys
14Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+11 more
Jun 17, 2026
May 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.
1Aiven
1Aiven
Jun 17, 2026
May 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerabili...Show more
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages missing schema qualifiers on privileged functions called by the aiven-extras extension. A low privileged user can create objects that collide with existing function names, which will then be executed instead. Exploiting this vulnerability could allow a low privileged user to acquire `superuser` privileges, which would allow full, unrestricted access to all data and database functions. And could lead to arbitrary code execution or data access on the underlying host as the `postgres` user. The issue has been patched as of version 1.1.9.Show less
1Ibm
1Security Verify Access
Jun 17, 2026
May 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-...Show more
IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.Show less
1Apache
1Openmeetings
Jun 17, 2026
May 12, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
1Linuxfoundation
1Vitess
Jun 17, 2026
May 11, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from...Show more
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will receive an error. Attempting to view the keyspace(s) will also no longer work. Creating a shard using `vtctldclient` does not have the same problem because the CLI validates the input correctly. Version 16.0.2, corresponding to version 0.16.2 of the `go` module, contains a patch for this issue. Some workarounds are available. Always use `vtctldclient` to create shards, instead of using VTAdmin; disable creating shards from VTAdmin using RBAC; and/or delete the topology record for the offending shard using the client for your topology server.Show less
1Rockwellautomation
2Armorstart St 281e Firmware
Armorstart St 284ee Firmware
Jun 17, 2026
May 11, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page. Show less
1Pimcore
1Customer Management Framework
Jun 17, 2026
May 11, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Co...Show more
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the unlogic in the counter value in the Conditions tab. Users should update to version 3.3.9 to receive a patch or, as a workaround, or apply the patch manually.Show less
1Selinc
10Sel 2241 Rtac Module Firmware
Sel 3350 FirmwareSel 3505 3 Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to arbitrarily alter the content...Show more
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to arbitrarily alter the content of a configuration file. See SEL Service Bulletin dated 2022-11-15 for more details.Show less
1Selinc
5Sel 3350 Firmware
Sel 3532 FirmwareSel 3555 Firmware+2 more
Jun 17, 2026
May 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow an authenticated remote attacker to use internal resources, allow...Show more
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow an authenticated remote attacker to use internal resources, allowing a variety of potential effects. See SEL Service Bulletin dated 2022-11-15 for more details.Show less
1Selinc
10Sel 2241 Rtac Module Firmware
Sel 3350 FirmwareSel 3505 3 Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See...Show more
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details. Show less
1Selinc
10Sel 2241 Rtac Module Firmware
Sel 3350 FirmwareSel 3505 3 Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See...Show more
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details. Show less
1Intel
10Server System D50tnp1mhcpac Firmware
Server System D50tnp1mhcrac FirmwareServer System D50tnp1mhcrlc Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.
1Intel
1Retail Edge Program
Jun 17, 2026
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable denial of service via local access.
1Intel
10Server System D50tnp1mhcpac Firmware
Server System D50tnp1mhcrac FirmwareServer System D50tnp1mhcrlc Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.
1Intel
10Server System D50tnp1mhcpac Firmware
Server System D50tnp1mhcrac FirmwareServer System D50tnp1mhcrlc Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.