CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validat...Show more |
1Hornerautomation 1Cscape Envisionrv Jun 17, 2026 Mar 25, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, w...Show more |
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulne...Show more |
The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk...Show more |
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future. |
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM pri...Show more |
1Nvidia 1Data Center Gpu Manager Jun 17, 2026 Mar 24, 2022 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privilege...Show more |
1Nozominetworks 2Cmc GuardianJun 17, 2026 Mar 24, 2022 8.6 HIGH· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using...Show more |
1Nozominetworks 2Cmc GuardianJun 17, 2026 Mar 24, 2022 8.6 HIGH· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the applianc...Show more |
A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system. |
1Ge 19Multilin B30 Firmware Multilin B90 FirmwareMultilin C30 Firmware+16 moreJun 17, 2026 Mar 23, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsuppor...Show more |
1Ge 19Multilin B30 Firmware Multilin B90 FirmwareMultilin C30 Firmware+16 moreJun 17, 2026 Mar 23, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. |
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. |
1Cyclonedx 1Bill Of Materials Repository Server Jun 17, 2026 Mar 22, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading...Show more |
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patche...Show more |
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. |
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service. |
In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation. This could lead to local esc...Show more |
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets. |