CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. |
Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash. |
1Tigera 2Calico Calico EnterpriseJun 17, 2026 Jun 6, 2022 N/A· v4 5.5 MEDIUM· v3 5.5 MEDIUM· v2 Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may...Show more |
1Schneider Electric 2Wiser Smart Eer21000 Firmware Wiser Smart Eer21001 FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when the user is tricked into performing certain actions on a webpage. Affected Products: Wiser Smart, E...Show more |
1Schneider Electric 1Powerlogic Ion Setup Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an I...Show more |
1Mitsubishi 3Melsec Iq R Rd81mes96n Firmware Melsec Lj71e71 100 FirmwareMelsec Qj71e71 100 FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number...Show more |
BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a...Show more |
2Dell Oracle5Bsafe Micro Edition Suite DatabaseHttp Server+2 moreJun 17, 2026 Jun 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. |
1Chat Server Project 1Chat Server Jun 17, 2026 May 31, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authP...Show more |
1Nextcloud 1Nextcloud Server Jun 17, 2026 May 31, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app password...Show more |
1Cisco 1Secure Network Analytics Jun 17, 2026 May 27, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administr...Show more |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 May 26, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22. |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 May 26, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22. |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 May 26, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22. |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 May 26, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22. |
1Dell 28Dell G5 5505 Firmware Inspiron 22 3275 FirmwareInspiron 24 3475 Firmware+25 moreJun 17, 2026 May 26, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. |
1Dell 28Dell G5 5505 Firmware Inspiron 22 3275 FirmwareInspiron 24 3475 Firmware+25 moreJun 17, 2026 May 26, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. |
1Zyxel 65Atp100 Firmware Atp100w FirmwareAtp200 Firmware+62 moreJun 17, 2026 May 24, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versi...Show more |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `tf.compat.v1.signal.rfft3d` lack input validation and under certain cond...Show more |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite int...Show more |