CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In valid_va_secbuf_check of drm_access_control.c, there is a possible ID due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not...Show more |
In ppmp_validate_wsm of drm_fw.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more |
In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. Us...Show more |
In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. Us...Show more |
In page_number of shared_mem.c, there is a possible code execution in secure world due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User i...Show more |
In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....Show more |
In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution p...Show more |
In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with no additional execut...Show more |
The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and pr...Show more |
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel p...Show more |
1Apple 4Ipados Iphone OsMacos+1 moreJun 17, 2026 Dec 15, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote u...Show more |
1Zabbix 2Web Service Report Generation Zabbix Agent2Jun 17, 2026 Dec 15, 2022 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files. |
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2. |
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software does not properly validate the input for a certain parameter in the s7ontcp.dll....Show more |
In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional e...Show more |
1Siemens 96Simatic Et 200 Sp Open Controller Cpu 1515sp Pc Firmware Simatic S7 1200 Cpu 1211c FirmwareSimatic S7 1200 Cpu 1212c Firmware+93 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. |
1Siemens 92Simatic Et 200 Sp Open Controller Cpu 1515sp Pc Firmware Simatic S7 1200 Cpu 1211c FirmwareSimatic S7 1200 Cpu 1212c Firmware+89 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. |
1Siemens 96Simatic Et 200 Sp Open Controller Cpu 1515sp Pc Firmware Simatic S7 1200 Cpu 1211c FirmwareSimatic S7 1200 Cpu 1212c Firmware+93 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. |
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the...Show more |
A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing ICAP request. The exploit can be triggered remotely by an attacker. |