CWE-20
12,948 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,948)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. |
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. |
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent....Show more |
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multi...Show more |
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th...Show more |
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of t...Show more |
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` n...Show more |
Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command execution. |
support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send...Show more |
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. |
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
|
1Amd 24Epyc 7003 Firmware Epyc 72f3 FirmwareEpyc 7313 Firmware+21 moreJun 17, 2026 Jan 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
|
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 2.4 LOW· v3 N/A· v2 Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
|
1Amd 64Epyc 7001 Firmware Epyc 7002 FirmwareEpyc 7003 Firmware+61 moreJun 17, 2026 Jan 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
|
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
|
1Amd 2Milanpi Firmware Romepi FirmwareJun 17, 2026 Jan 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.
|
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.
|
1Amd 2Milanpi Firmware Romepi FirmwareJun 17, 2026 Jan 11, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.
|
1Amd 23Epyc 7003 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 Jan 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
|
1Amd 147Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+144 moreJun 17, 2026 Jan 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution. |