← Back
CWE-20

12,948 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,948)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freeradius
1Freeradius
Jun 17, 2026
Jan 17, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.
1Publify Project
1Publify
Jun 17, 2026
Jan 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
1Netdata
1Netdata
Jun 17, 2026
Jan 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent....Show more
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent. When an alert is triggered, the function `health_alarm_execute` is called. This function performs different checks and then enqueues a command by calling `spawn_enq_cmd`. This command is populated with several arguments that are not sanitized. One of them is the `registry_hostname` of the node for which the alert is raised. By providing a specially crafted `registry_hostname` as part of the health data that is streamed to a Netdata (parent) agent, an attacker can execute arbitrary commands at the remote host as a side-effect of the raised alert. Note that the commands are executed as the user running the Netdata Agent. This user is usually named `netdata`. The ability to run arbitrary commands may allow an attacker to escalate privileges by escalating other vulnerabilities in the system, as that user. The problem has been fixed in: Netdata agent v1.37 (stable) and Netdata agent v1.36.0-409 (nightly). As a workaround, streaming is not enabled by default. If you have previously enabled this, it can be disabled. Limiting access to the port on the recipient Agent to trusted child connections may mitigate the impact of this vulnerability.Show less
1Nextcloud
1Deck
Jun 17, 2026
Jan 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multi...Show more
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is recommended that the Nextcloud Server is upgraded to 1.6.5 or 1.7.3 or 1.8.2.Show less
1Adobe
1Incopy
Jun 17, 2026
Jan 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th...Show more
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Indesign
Jun 17, 2026
Jan 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of t...Show more
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Gatsbyjs
1Gatsby
Jun 17, 2026
Jan 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` n...Show more
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized. The vulnerability is present in gatsby-transformer-remark when passing input in data mode (querying MarkdownRemark nodes via GraphQL). Injected JavaScript executes in the context of the build server. To exploit this vulnerability untrusted/unsanitized input would need to be sourced by or added into a file processed by gatsby-transformer-remark. A patch has been introduced in `gatsby-transformer-remark@5.25.1` and `gatsby-transformer-remark@6.3.2` which mitigates the issue by disabling the `gray-matter` JavaScript Frontmatter engine. As a workaround, if an older version of `gatsby-transformer-remark` must be used, input passed into the plugin should be sanitized ahead of processing. It is encouraged for projects to upgrade to the latest major release branch for all Gatsby plugins to ensure the latest security updates and bug fixes are received in a timely manner.Show less
1Alotceriot
1Ar7088h A Firmware
Jun 17, 2026
Jan 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command execution.
1Cloudflare
1Warp
Jun 17, 2026
Jan 11, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send...Show more
support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option. An attacker with access to the local file system could use a crafted XML config file pointing to a malicious file or set a local path to the executable using Cloudflare Zero Trust Dashboard (for Zero Trust enrolled clients). Show less
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Jan 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
1Amd
24Epyc 7003 Firmware
Epyc 72f3 FirmwareEpyc 7313 Firmware+21 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
1Amd
64Epyc 7001 Firmware
Epyc 7002 FirmwareEpyc 7003 Firmware+61 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
1Amd
2Milanpi Firmware
Romepi Firmware
Jun 17, 2026
Jan 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.
1Amd
1Milanpi Sp3 Firmware
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.
1Amd
2Milanpi Firmware
Romepi Firmware
Jun 17, 2026
Jan 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.
1Amd
23Epyc 7003 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
1Amd
147Athlon 3050ge Firmware
Athlon 3150g FirmwareAthlon 3150ge Firmware+144 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.