CWE-20
12,710 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,710)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope i...Show more |
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of...Show more |
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML pa...Show more |
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from...Show more |
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es...Show more |
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. Thi...Show more |
A
security flaw was discovered in the NETGEAR WAX333 Access Point that could
allow someone already logged in and connected to the local network to make
unauthorized changes to the device's settings |
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers
that could allow someone already logged in to the device to run unauthorized commands
or code on the router. |
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized ch...Show more |
1Microsoft 8365 Apps Microsoft 365Office 2019+5 moreJul 16, 2026 Jul 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 16, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 21, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreJul 20, 2026 Jul 14, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreJul 20, 2026 Jul 14, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. |
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled r...Show more |
1Microsoft 7365 Apps ExcelMicrosoft 365+4 moreJul 16, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HT...Show more |
In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request contains a valid signal_id...Show more |
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification. This can be used...Show more |
A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component...Show more |