← Back
CWE-20

12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,947)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
2Keycloak
Single Sign On
Jun 17, 2026
Aug 26, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets t...Show more
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.Show less
1Lexmark
117B2236 Firmware
B2338 FirmwareB2442 Firmware+114 more
Jun 17, 2026
Aug 26, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
4Debian
LinuxNetapp+1 more
8Debian Linux
Enterprise LinuxH300s Firmware+5 more
Jun 17, 2026
Aug 24, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal informat...Show more
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.Show less
1Redhat
1Openshift
Jun 17, 2026
Aug 24, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenSh...Show more
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.Show less
1Redhat
1Ansible Runner
Jun 17, 2026
Aug 24, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could un...Show more
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.Show less
1Redhat
1Keycloak
Jun 17, 2026
Aug 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulner...Show more
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.Show less
1Redhat
1Openshift Api Management
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vu...Show more
A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vulnerability is to data confidentiality.Show less
1Apache
1Flume
Jun 17, 2026
Aug 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP se...Show more
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.Show less
1Intel
2Lapbc510 Firmware
Lapbc710 Firmware
Jun 17, 2026
Aug 18, 2022
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.
1Intel
2Lapbc510 Firmware
Lapbc710 Firmware
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Data Center Manager
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.
1Intel
9Proset Wi Fi 6e Ax210 Firmware
Wi Fi 6 Ax200 FirmwareWi Fi 6 Ax201 Firmware+6 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1Intel
9Proset Wi Fi 6e Ax210 Firmware
Wi Fi 6 Ax200 FirmwareWi Fi 6 Ax201 Firmware+6 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.
1Intel
7Dual Band Wireless Ac 8260 Firmware
Dual Band Wireless Ac 8265 FirmwareKiller Ac 1550 Firmware+4 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
9Killer Ac 1550 Firmware
Killer Wi Fi 6 Ax1650 FirmwareKiller Wi Fi 6e Ax1675 Firmware+6 more
Jun 17, 2026
Aug 18, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1Hyperledger
1Fabric
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the...Show more
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.Show less
3Debian
FedoraprojectLibtiff
3Debian Linux
FedoraLibtiff
Jun 17, 2026
Aug 17, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
1Wisa
1Smart Wing Cms
Jun 17, 2026
Aug 17, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
1Moodle
1Moodle
Jun 17, 2026
Aug 16, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
1Contec
2Sv Cpt Mc310 Firmware
Sv Cpt Mc310f Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerabilit...Show more
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.Show less