CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/message-bus/_diagnostics` path. The impact of this vulnerability is greate...Show more |
In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...Show more |
In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee...Show more |
1Mediatek 2Mt7615 Firmware Mt7622 FirmwareJun 17, 2026 Jan 4, 2022 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of service from a proximal attacker with no additional execution privileges needed. User interaction is...Show more |
PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed. |
1Stars Rating Project 1Stars Rating Jun 17, 2026 Jan 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if t...Show more |
1Smr 1Shenwang Endpoint Protection Security System Jun 17, 2026 Jan 3, 2022 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 The programming function of Shockwall system has an improper input validation vulnerability. An authenticated attacker within the local area network can send malicious response to the server to disrupt the service partia...Show more |
1Qualcomm 126Ar8031 Firmware Ar8035 FirmwareCsr8811 Firmware+123 moreJun 17, 2026 Jan 3, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna...Show more |
Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascrip...Show more |
5Apache CiscoDebian+2 more22Cloudcenter Communications Brm Elastic Charging EngineCommunications Diameter Signaling Router+19 moreJun 17, 2026 Dec 28, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so...Show more |
1Philips 1Patient Information Center Ix Jun 17, 2026 Dec 27, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly. |
1Simple Asn1 Project 1Simple Asn1 Jun 17, 2026 Dec 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f. |
1Raw Cpuid Project 1Raw Cpuid Jun 17, 2026 Dec 27, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 An issue was discovered in the raw-cpuid crate before 9.1.1 for Rust. If the serialize feature is used (which is not the the default), a Deserialize operation may lack sufficient validation, leading to memory corruption...Show more |
1Mediatek 8Mt7603e Firmware Mt7612 FirmwareMt7613 Firmware+5 moreJun 17, 2026 Dec 26, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT791...Show more |
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the networ...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. |
An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before 2022.12. Crafted data in a BMP file can trigger a write operation past the end of an allocated buff...Show more |
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions. |
5Apache DebianNetapp+2 more1166bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+113 moreJun 17, 2026 Dec 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t...Show more |