CWE-20
12,948 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,948)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 13Windows 10 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Active Directory Domain Services API Denial of Service Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Feb 14, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not d...Show more |
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged use...Show more |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Feb 14, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup tables with unnecessary filename extensions. Lookup table file extensions may now be one of the foll...Show more |
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher p...Show more |
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requi...Show more |
1Siemens 2Sipass Integrated Ac5102 (acc G2) Firmware Sipass Integrated Acc Ap FirmwareJun 17, 2026 Feb 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V2.85.44), SiPass integrated ACC-AP (All versions < V2.85.43). Affected devices improperly sanitize user input on the telnet comman...Show more |
Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request |
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion.
This issue affects Smartpower Web: before 23.01.01. |
1Qualcomm 96Csr8811 Firmware Ipq5010 FirmwareIpq5018 Firmware+93 moreJun 17, 2026 Feb 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to improper input validation in WLAN Host. |
1Qualcomm 97Csr8811 Firmware Ipq5010 FirmwareIpq5018 Firmware+94 moreJun 17, 2026 Feb 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation. |
1Qualcomm 18Qam8295p Firmware Qca6574a FirmwareQca6574au Firmware+15 moreJun 17, 2026 Feb 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient Denial-of-service in Automotive due to improper input validation while parsing ELF file. |
1Qualcomm 30Ar8031 Firmware Csra6620 FirmwareCsra6640 Firmware+27 moreJun 17, 2026 Feb 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption in modem due to improper length check while copying into memory |
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subject to a command inje...Show more |
Dell Alienware Command Center versions 5.5.37.0 and prior contain an Improper Input validation vulnerability. A local authenticated malicious user could potentially send malicious input to a named pipe in order to eleva...Show more |
There is a vulnerability in 21.328.01.00.00 version of the E5573Cs-322. Remote attackers could exploit this vulnerability to make the network where the E5573Cs-322 is running temporarily unavailable.
|
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions. |
Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles. |
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities. |