CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until r...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Jun 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker. |
1Qualcomm 113Apq8009 Firmware Apq8009w FirmwareApq8096au Firmware+110 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon...Show more |
1Qualcomm 38Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+35 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile |
1Qualcomm 83Apq8053 Firmware Apq8096au FirmwareAqt1000 Firmware+80 moreJun 17, 2026 Jun 14, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrago...Show more |
1Qualcomm 2Sd850 Firmware Sdxr1 FirmwareJun 17, 2026 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute |
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP ser...Show more |
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have contr...Show more |
1Huawei 3Emui HarmonyosMagic UiJun 17, 2026 Jun 13, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation. |
Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields can be configured to allow only certain file extensions to be uploaded b...Show more |
1Verbatim 4Executive Fingerprint Secure Ssd Firmware Fingerprint Secure Portable Hard Drive FirmwareKeypad Secure Usb 3.2 Gen 1 Firmware+1 moreJun 17, 2026 Jun 8, 2022 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g.,...Show more |
1Hitachienergy 1Txpert Hub Coretec 4 Firmware Jun 17, 2026 Jun 7, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights...Show more |
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code. |
Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence. |
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash. |
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash. |
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash. |
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. |
Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. |
Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. |