← Back
CWE-20

12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,947)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Mq
Jun 17, 2026
Nov 11, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335.
1Intel
8Nuc11dbbi7 Firmware
Nuc11dbbi9 FirmwareNuc 11 Compute Element Cm11ebc4w Firmware+5 more
Jun 17, 2026
Nov 11, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
2Nuc Board De3815tybe Firmware
Nuc Kit De3815tykhe Firmware
Jun 17, 2026
Nov 11, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
11Nuc 11 Performance Kit Nuc11pahi30z Firmware
Nuc 11 Performance Kit Nuc11pahi3 FirmwareNuc 11 Performance Kit Nuc11pahi50z Firmware+8 more
Jun 17, 2026
Nov 11, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of p...Show more
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access.Show less
1Intel
3R1000wf Firmware
R2000wf FirmwareS2600wf Firmware
Jun 17, 2026
Nov 11, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System R2000WF families before version R02.01.0014 may allow a privileged user to poten...Show more
Improper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System R2000WF families before version R02.01.0014 may allow a privileged user to potentially enable an escalation of privilege via local access.Show less
1Intel
1Server Platform Services Firmware
Jun 17, 2026
Nov 11, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in firmware for Intel(R) SPS before version SPS_E3_04.01.04.700.0 may allow an authenticated user to potentially enable denial of service via local access.
1Intel
1Xmm 7560 Firmware
Jun 17, 2026
Nov 11, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.
1Intel
1Xmm 7560 Firmware
Jun 17, 2026
Nov 11, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
342Converged Security And Manageability Engine
Core I3 1000g1 FirmwareCore I3 1000g4 Firmware+339 more
Jun 17, 2026
Nov 11, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access.
1Intel
130Core I5 7640x Firmware
Core I7 3820 FirmwareCore I7 3920xm Firmware+127 more
Jun 17, 2026
Nov 11, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Openvino
Jun 17, 2026
Nov 11, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access.
1Intel
1M10jnp2sb Firmware
Jun 17, 2026
Nov 10, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a privileged user to potentially enable an escalation of privilege via local access.
1Samsung
1Exynos Firmware
Jun 17, 2026
Nov 9, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.
1Google
1Android
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.
1Grafana
1Grafana
Jun 17, 2026
Nov 9, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organiza...Show more
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Nov 9, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to star...Show more
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.Show less
1Amd
1Amd Uprof
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.
1Amd
1Amd Uprof
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.
4Debian
FedoraprojectVarnish Software+1 more
5Debian Linux
FedoraVarnish Cache+2 more
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in th...Show more
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.Show less
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Nov 8, 2022
N/A· v4
8.7 HIGH· v3
N/A· v2
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted....Show more
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application. Show less