CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafted URL may allow a remote unauthenticated attacker to set a specially crafted URL...Show more |
Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to retrieve files with specific e...Show more |
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions...Show more |
3Debian FedoraprojectGitpython Project3Debian Linux FedoraGitpythonJun 17, 2026 Dec 6, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting...Show more |
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is...Show more |
1Nttdata 2Terasoluna Global Framework Terasoluna Server Framework For Java (rich)Jun 17, 2026 Dec 5, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spri...Show more |
2Apache Debian2Commons Net Debian LinuxJun 17, 2026 Dec 3, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the maliciou...Show more |
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml...Show more |
1Mitsubishielectric 6R04encpu Firmware R08encpu FirmwareR120encpu Firmware+3 moreJun 17, 2026 Nov 30, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network...Show more |
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTM...Show more |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Nov 29, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers...Show more |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Nov 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that a...Show more |
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges. |
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text....Show more |
1Decode Uri Component Project 1Decode Uri Component Jun 17, 2026 Nov 28, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS. |
2Fedoraproject Nextcloud3Fedora Nextcloud Enterprise ServerNextcloud ServerJun 17, 2026 Nov 25, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a d...Show more |
1Nextcloud 1Openid Connect User Backend Jun 17, 2026 Nov 25, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the...Show more |
1Mitsubishielectric 3Got2000 Gt23 Firmware Got2000 Gt25 FirmwareGot2000 Gt27 FirmwareJun 17, 2026 Nov 24, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability in Mitsubishi Electric GOT2000 Series GT27 model FTP server versions 01.39.000 and prior, Mitsubishi Electric GOT2000 Series GT25 model FTP server versions 01.39.000 and prior and...Show more |
iTerm2 before 3.4.18 mishandles a DECRQSS response. |
Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack...Show more |