← Back
CWE-20

12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,947)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
34Alienware M15 R5 Firmware
G15 5515 FirmwareG5 Se 5505 Firmware+31 more
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security con...Show more
Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.Show less
1Bosch
1Pra Es8p2s Firmware
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
1Broadcom
1Ca Automic Automation
Jun 17, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.
1Broadcom
1Ca Automic Automation
Jun 17, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.
1Synaptics
1Fingerprint Driver
Jun 17, 2026
Jun 16, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synapt...Show more
Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.Show less
1Intel
407Celeron 5305u Firmware
Celeron G3900 FirmwareCeleron G3900t Firmware+404 more
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local access.
1Splunk
2Splunk
Splunk Cloud Platform
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.1 HIGH· v3
4.0 MEDIUM· v2
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for...Show more
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#New_capabilities_can_limit_access_to_some_custom_and_potentially_risky_commands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will.Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input validation. This could lead to local information disclosure with no additional execution privileges ne...Show more
In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-215212561Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed...Show more
In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-215001024References: N/AShow less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...Show more
In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-212803946References: N/AShow less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due to improper input validation. This could lead to local escalation of privilege with no additional e...Show more
In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-218341397Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no addit...Show more
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-217934478Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated Scalable Vector Graphics (.svg, svg.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user unt...Show more
When a user opens manipulated Scalable Vector Graphics (.svg, svg.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until resta...Show more
When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user...Show more
When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user unti...Show more
When a user opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of...Show more
When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated Encapsulated Post Script (.eps, ai.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user unti...Show more
When a user opens manipulated Encapsulated Post Script (.eps, ai.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the us...Show more
When a user opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart...Show more
When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less