CWE-20
12,949 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 20h2+9 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
Microsoft Edge (Chromium-based) Tampering Vulnerability |
Raw Image Extension Remote Code Execution Vulnerability |
1Microsoft 8Windows 10 1809 Windows 10 20h2Windows 10 21h2+5 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Win32k Elevation of Privilege Vulnerability |
Visual Studio Code Remote Code Execution Vulnerability |
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 20h2+9 moreJun 17, 2026 Apr 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom d...Show more |
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automat...Show more |
1Lexmark 26Cslbl Firmware Cslbn FirmwareCsnzj Firmware+23 moreJun 17, 2026 Apr 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4). |
1Lexmark 26Cslbl Firmware Cslbn FirmwareCsnzj Firmware+23 moreJun 17, 2026 Apr 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4). |
1Lexmark 26Cslbl Firmware Cslbn FirmwareCsnzj Firmware+23 moreJun 17, 2026 Apr 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). |
1Lexmark 26Cslbl Firmware Cslbn FirmwareCsnzj Firmware+23 moreJun 17, 2026 Apr 10, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). |
rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must re...Show more |
1Apache 1Apache Airflow Providers Apache Spark Jun 17, 2026 Apr 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1.
|
1Apache 1Apache Airflow Providers Apache Drill Jun 17, 2026 Apr 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2. |
A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device. This vulnerability is due to insufficient validation of user...Show more |
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more...Show more |
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more...Show more |