CWE-20
12,948 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,948)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in Sengled Smart bulb 0x0000024 allows attackers to arbitrarily perform a factory reset on the device via a crafted IEEE 802.15.4 frame. |
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9....Show more |
1Lexmark 128B2236 Firmware B2338 FirmwareB2442 Firmware+125 moreJun 17, 2026 Jan 23, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. |
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known. |
Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40. |
1Ibm 1Infosphere Information Server Jun 17, 2026 Jan 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2
IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. IBM X-Force ID: 237583.
|
1Cisco 4Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+1 moreJun 17, 2026 Jan 20, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating sys...Show more |
1Cisco 4Rv016 Firmware Rv042 FirmwareRv042g Firmware+1 moreJun 17, 2026 Jan 20, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affecte...Show more |
1Cisco 2Broadworks Application Delivery Platform Device Management Broadworks Xtended Services PlatformJun 17, 2026 Jan 20, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a den...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution...Show more |
1Zohocorp 22Manageengine Access Manager Plus Manageengine Ad360Manageengine Adaudit Plus+19 moreJul 31, 2026 Jan 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT feature...Show more |
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability...Show more |
Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability...Show more |
1Dell 26G5 Se 5505 Firmware Inspiron 27 7775 FirmwareInspiron 3180 Firmware+23 moreJun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM....Show more |
1Dell 26G5 Se 5505 Firmware Inspiron 27 7775 FirmwareInspiron 3180 Firmware+23 moreJun 17, 2026 Jan 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
|
1Dell 3Edge Gateway 3000 Firmware Edge Gateway 5000 FirmwareEmbedded Box Pc 3000 FirmwareJun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
|
1Sewio 1Real Time Location System Studio Jun 17, 2026 Jan 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to several modules and services of the software. This could allow a...Show more |
1Sewio 1Real Time Location System Studio Jun 17, 2026 Jan 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to the service_start, service_stop, and service_restart modules of...Show more |
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a r...Show more |
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the...Show more |