CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing packa...Show more |
Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller. |
1Cisco 3Adaptive Security Appliance Software Firepower Threat DefenseSecure Firewall Threat DefenseAug 11, 2026 May 3, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote at...Show more |
1Cisco 3Adaptive Security Appliance Software Firepower Threat DefenseSecure Firewall Threat DefenseAug 11, 2026 May 3, 2022 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denia...Show more |
This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString va...Show more |
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. |
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buf...Show more |
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow,...Show more |
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer...Show more |
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine...Show more |
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA. |
1Lenovo 1Thinkpad X1 Fold Gen 1 Firmware Jun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute a...Show more |
1Lenovo 30Thinkpad 11e Firmware Thinkpad 11e Yoga FirmwareThinkpad Helix Firmware+27 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privil...Show more |
1Lenovo 62C340 14iml Firmware C340 15iml FirmwareD330 10igm Firmware+59 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
1Lenovo 53A340 22icb Firmware A340 22ick FirmwareA340 24icb Firmware+50 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to exe...Show more |
1Lenovo 32A540 24icb Firmware A540 27icb FirmwareIdeacentre 5 14imb05 Firmware+29 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitra...Show more |
1Lenovo 105Ideapad 3 14ada05 Firmware Ideapad 3 14ada6 FirmwareIdeapad 3 14alc6 Firmware+102 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code. |
1Dell 1Integrated Dell Remote Access Controller 8 Firmware Jun 17, 2026 Apr 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to cause resource exhaustion in the webserver, resulting...Show more |
1Cisco 2Roomos Telepresence Collaboration EndpointJun 17, 2026 Apr 21, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (Do...Show more |
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the...Show more |