CWE-20
12,948 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,948)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-9]$ regular expression. |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Overlay Filter Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 1809 Windows 10 20h2Windows 10 21h2+5 moreJun 17, 2026 Jan 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Cryptographic Information Disclosure Vulnerability |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Error Reporting Service Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 1809 Windows 10 20h2Windows 10 21h2+5 moreJun 17, 2026 Jan 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Cryptographic Information Disclosure Vulnerability |
1Microsoft 8Windows 10 1809 Windows 10 20h2Windows 10 21h2+5 moreJun 17, 2026 Jan 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Cryptographic Information Disclosure Vulnerability |
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: L...Show more |
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb). |
1Qualcomm 51Qam8295p Firmware Qca6174a FirmwareQca6390 Firmware+48 moreJun 17, 2026 Jan 9, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Automotive Android OS due to improper input validation. |
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `...Show more |
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on...Show more |
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Encodin...Show more |
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1....Show more |
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: AL...Show more |
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: AL...Show more |
1Kenny2automate Project 1Kenny2automate Jun 17, 2026 Jan 2, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 kenny2automate is a Discord bot. In the web interface for server settings, form elements were generated with Discord channel IDs as part of input names. Prior to commit a947d7c, no validation was performed to ensure that...Show more |
NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local attacker to cause information disclosure and compromise integrity. The scop...Show more |
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service. |
Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application service abnormal. |