← Back
CWE-20

12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,947)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until r...Show more
When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.Show less
1Siemens
1Sinema Remote Connect Server
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker.
1Qualcomm
113Apq8009 Firmware
Apq8009w FirmwareApq8096au Firmware+110 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon...Show more
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon WearablesShow less
1Qualcomm
38Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+35 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile
1Qualcomm
83Apq8053 Firmware
Apq8096au FirmwareAqt1000 Firmware+80 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrago...Show more
Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & MusicShow less
1Qualcomm
2Sd850 Firmware
Sdxr1 Firmware
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute
1Apache
1Flume
Jun 17, 2026
Jun 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP ser...Show more
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.Show less
1Electronjs
1Electron
Jun 17, 2026
Jun 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have contr...Show more
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto updating infrastructure and the ease of that attack entirely depends on the potential victim's infrastructure security. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. There are no known workarounds.Show less
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Jun 13, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
1Maykinmedia
1Open Forms
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields can be configured to allow only certain file extensions to be uploaded b...Show more
Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields can be configured to allow only certain file extensions to be uploaded by end users (e.g. only PDF / Excel / ...). The input validation of uploaded files is insufficient in versions prior to 1.0.9 and 1.1.1. Users could alter or strip file extensions to bypass this validation. This results in files being uploaded to the server that are of a different file type than indicated by the file name extension. These files may be downloaded (manually or automatically) by staff and/or other applications for further processing. Malicious files can therefore find their way into internal/trusted networks. Versions 1.0.9 and 1.1.1 contain patches for this issue. As a workaround, an API gateway or intrusion detection solution in front of open-forms may be able to scan for and block malicious content before it reaches the Open Forms application.Show less
1Verbatim
4Executive Fingerprint Secure Ssd Firmware
Fingerprint Secure Portable Hard Drive FirmwareKeypad Secure Usb 3.2 Gen 1 Firmware+1 more
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g.,...Show more
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.Show less
1Hitachienergy
1Txpert Hub Coretec 4 Firmware
Jun 17, 2026
Jun 7, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights...Show more
Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights to inject an OS command that is executed by the system. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0; 2.0.1; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.Show less
1Samsung
1Kies
Jun 17, 2026
Jun 7, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.
1Google
1Android
Jun 17, 2026
Jun 7, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.
1Google
1Android
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
1Google
1Android
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
1Google
1Android
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
1Google
1Android
Jun 17, 2026
Jun 7, 2022
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
1Google
1Android
Jun 17, 2026
Jun 7, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
1Google
1Android
Jun 17, 2026
Jun 7, 2022
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.