CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 48Agilex 7 Fpga F Series 006 Firmware Agilex 7 Fpga F Series 008 FirmwareAgilex 7 Fpga F Series 012 Firmware+45 moreJun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 117Cm11ebc4w Firmware Cm11ebi38w FirmwareCm11ebi58w Firmware+114 moreJun 17, 2026 May 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, Intel(R) NUC 11 C...Show more |
1Intel 13Cm11ebc4w Firmware Cm11ebi38w FirmwareCm11ebi58w Firmware+10 moreJun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in firmware for Intel(R) NUC 8 Compute Element, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element may allow a privileged user to enable escalation of privilege via local access. |
1Intel 41Cm8ccb4r Firmware Cm8i3cb4n FirmwareCm8i5cb8n Firmware+38 moreJun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC...Show more |
1Intel 273Core I3 1000g1 Firmware Core I3 1000g4 FirmwareCore I3 1005g1 Firmware+270 moreJun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 1Compute Stick Stk2mv64cc Firmware Jun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 3Nuc5cpyh Firmware Nuc5pgyh FirmwareNuc5ppyh FirmwareJun 17, 2026 May 10, 2023 N/A· v4 6.0 MEDIUM· v3 N/A· v2 Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable information disclosure or denial of service via local access |
1Intel 19Nuc7cjyh Firmware Nuc7cjyhn FirmwareNuc7cjysal Firmware+16 moreJun 17, 2026 May 10, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper input validation for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. |
Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of service via local access. |
When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/rand.Read() returns an error. In rare deployment cases (error thrown by the Read() function), this coul...Show more |
1Amd 63Ryzen 1200 (af) Firmware Ryzen 1600 (af) FirmwareRyzen 2200g Firmware+60 moreJun 17, 2026 May 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient input validation in ABL may enable
a privileged attacker to corrupt ASP memory, potentially resulting in a loss of
integrity or code execution.
|
1Amd 63Epyc 7232p Firmware Epyc 7251 FirmwareEpyc 7252 Firmware+60 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in...Show more |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management U...Show more |
1Amd 23Epyc 72f3 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation on the model
specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest
memory integrity.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper input validation in ABL may enable an
attacker with physical access, to perform arbitrary memory overwrites,
potentially leading to a loss of integrity and code execution.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient syscall input validation in the ASP
Bootloader may allow a privileged attacker to execute arbitrary DMA copies,
which can lead to code execution.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Insufficient input validation in the SMU may
allow an attacker to corrupt SMU SRAM potentially leading to a loss of
integrity or denial of service. |
1Microsoft 16365 Apps OfficeOffice Long Term Servicing Channel+13 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Microsoft Word Security Feature Bypass Vulnerability |
1Microsoft 2Sharepoint Enterprise Server Sharepoint ServerJun 17, 2026 May 9, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft SharePoint Server Spoofing Vulnerability |
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kern...Show more |