← Back
CWE-20

12,948 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,948)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Personnummer
1Personnummer
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-9]$ regular expression.
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Overlay Filter Elevation of Privilege Vulnerability
1Microsoft
15Windows 10 1607
Windows 10 1809Windows 10 20h2+12 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
8Windows 10 1809
Windows 10 20h2Windows 10 21h2+5 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Cryptographic Information Disclosure Vulnerability
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Error Reporting Service Elevation of Privilege Vulnerability
1Microsoft
8Windows 10 1809
Windows 10 20h2Windows 10 21h2+5 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Cryptographic Information Disclosure Vulnerability
1Microsoft
8Windows 10 1809
Windows 10 20h2Windows 10 21h2+5 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Cryptographic Information Disclosure Vulnerability
1Google
1Chrome
Jun 17, 2026
Jan 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: L...Show more
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Low)Show less
1Circl
1Pandora
Jun 17, 2026
Jan 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
1Qualcomm
51Qam8295p Firmware
Qca6174a FirmwareQca6390 Firmware+48 more
Jun 17, 2026
Jan 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Automotive Android OS due to improper input validation.
1Discourse
1Discourse
Jun 17, 2026
Jan 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `...Show more
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that are not counted toward the character limit. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.Show less
1Typelevel
1Http4s
Jun 17, 2026
Jan 4, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on...Show more
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface.Show less
1Protocol
1Go Ipld Prime
Jun 17, 2026
Jan 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Encodin...Show more
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Encoding data which contains a Bytes kind Node will pass a Bytes token to the JSON encoder which will panic as it doesn't expect to receive Bytes tokens. Such an encode should be treated as an error, as plain JSON should not be able to encode Bytes. This only impacts uses of the `json` codec. `dag-json` is not impacted. Use of `json` as a decoder is not impacted. This issue is fixed in v0.19.0. As a workaround, one may prefer the `dag-json` codec, which has the ability to encode bytes.Show less
1Apache
1Dolphinscheduler
Jun 17, 2026
Jan 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1....Show more
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.Show less
1Google
1Android
Jun 17, 2026
Jan 3, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: AL...Show more
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262518; Issue ID: ALPS07262518.Show less
1Google
1Android
Jun 17, 2026
Jan 3, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: AL...Show more
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262617; Issue ID: ALPS07262617.Show less
1Kenny2automate Project
1Kenny2automate
Jun 17, 2026
Jan 2, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
kenny2automate is a Discord bot. In the web interface for server settings, form elements were generated with Discord channel IDs as part of input names. Prior to commit a947d7c, no validation was performed to ensure that...Show more
kenny2automate is a Discord bot. In the web interface for server settings, form elements were generated with Discord channel IDs as part of input names. Prior to commit a947d7c, no validation was performed to ensure that the channel IDs submitted actually belonged to the server being configured. Thus anyone who has access to the channel ID they wish to change settings for and the server settings panel for any server could change settings for the requested channel no matter which server it belonged to. Commit a947d7c resolves the issue and has been deployed to the official instance of the bot. The only workaround that exists is to disable the web config entirely by changing it to run on localhost. Note that a workaround is only necessary for those who run their own instance of the bot.Show less
1Nvidia
1Jetson Linux
Jun 17, 2026
Dec 30, 2022
N/A· v4
7.9 HIGH· v3
N/A· v2
NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local attacker to cause information disclosure and compromise integrity. The scop...Show more
NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local attacker to cause information disclosure and compromise integrity. The scope of the impact can extend to other components.Show less
1Nvidia
2Cloud Gaming
Virtual Gpu
Jun 17, 2026
Dec 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service.
1Huawei
1Aslan Al10 Firmware
Jun 17, 2026
Dec 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application service abnormal.