CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phoenixcontact 3Rad Ism 900 En Bd Bus Firmware Rad Ism 900 En Bd/b FirmwareRad Ism 900 En Bd FirmwareJun 17, 2026 May 11, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation i...Show more |
Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other...Show more |
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by i...Show more |
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly ha...Show more |
1Amd 23Epyc 72f3 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 May 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application. |
1Amd 49Epyc 7002 Firmware Epyc 7232p FirmwareEpyc 7252 Firmware+46 moreJun 17, 2026 May 10, 2022 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents re...Show more |
In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operations. Using these flaws, malicious firmware code can elevate privileges,...Show more |
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulnerability when parsing a PCX file that could result in arbitrary code execution in the context of the...Show more |
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted m...Show more |
In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an attacker to potentially inject arbitrary content into the web page (e.g...Show more |
2Fedoraproject Keylime2Fedora KeylimeJun 17, 2026 May 6, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use o...Show more |
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the...Show more |
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API gr...Show more |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 May 5, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x,...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS profile is configured on a virtual server, an undisclosed DNS response can...Show more |
1F5 1Big Ip Advanced Firewall Manager Jun 17, 2026 May 5, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, an authenticated attacker with high privileges can upload a m...Show more |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 May 5, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authenticated attacker with high privileges to manipulate the APM policy leadi...Show more |
1Ibm 2Robotic Process Automation Robotic Process Automation As A ServiceJun 17, 2026 May 5, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce th...Show more |
1Cisco 1Enterprise Nfv Infrastructure Software Jun 17, 2026 May 4, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level,...Show more |
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to exi...Show more |