← Back
CWE-20

12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,947)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amd
1Radeon Software
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS).
1Amd
1Radeon Software
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution .
1Dell
283Alienware 13 R3 Firmware
Alienware 15 R3 FirmwareAlienware 15 R4 Firmware+280 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
1Dell
283Alienware 13 R3 Firmware
Alienware 15 R3 FirmwareAlienware 15 R4 Firmware+280 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
1Dell
283Alienware 13 R3 Firmware
Alienware 15 R3 FirmwareAlienware 15 R4 Firmware+280 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
1Lenovo
29Thinkpad 11e 3rd Gen Firmware
Thinkpad 11e 4th Gen Celeron FirmwareThinkpad 11e 4th Gen I3 Firmware+26 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1Lenovo
133Ideapad S940 14iwl Firmware
Ideapad Yoga S940 14iwl FirmwareThinkpad 10 Firmware+130 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
1Lenovo
20Thinkcentre E93 Firmware
Thinkcentre M4500q FirmwareThinkcentre M600 Firmware+17 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and...Show more
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.Show less
1Lenovo
133Ideapad S940 14iwl Firmware
Ideapad Yoga S940 14iwl FirmwareThinkpad 10 Firmware+130 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1Ibm
2Security Guardium Key Lifecycle Manager
Security Key Lifecycle Manager
Jun 17, 2026
Nov 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and corre...Show more
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.Show less
1Ibm
2Security Guardium Key Lifecycle Manager
Security Key Lifecycle Manager
Jun 17, 2026
Nov 12, 2021
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and corre...Show more
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.Show less
1Ibm
2Security Guardium Key Lifecycle Manager
Security Key Lifecycle Manager
Jun 17, 2026
Nov 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and corre...Show more
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.Show less
1Qualcomm
163Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+160 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesShow less
1Zoom
5Zoom On Premise Meeting Connector Controller
Zoom On Premise Meeting Connector MmrZoom On Premise Recording Connector+2 more
Jun 17, 2026
Nov 11, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Record...Show more
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.Show less
2Cloudflare
Debian
2Debian Linux
Octorpki
Jun 17, 2026
Nov 11, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
2Cloudflare
Debian
2Debian Linux
Octorpki
Jun 17, 2026
Nov 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
2Cloudflare
Debian
2Debian Linux
Octorpki
Jun 17, 2026
Nov 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the bas...Show more
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.Show less
2Oracle
Pypa
4Agile Plm
Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Policy+1 more
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vul...Show more
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.Show less
1Siemens
1Simatic Rtls Locating Manager
Jun 17, 2026
Nov 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application does not properly handle the import of large configuration files. A local attacker could import a spec...Show more
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application does not properly handle the import of large configuration files. A local attacker could import a specially crafted file which could lead to a denial-of-service condition of the application service.Show less
3Fedoraproject
GolangOracle
3Fedora
GoTimesten In Memory Database
Jun 17, 2026
Nov 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.