CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper input validation in some Intel(R) Graphics Drivers before version 27.20.100.8935 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privileges. |
Due to improper input validation in InfraBox, logs can be modified by an authenticated user. |
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968. |
1Dreamsecurity 1Magicline4nx.exe Jun 17, 2026 Aug 6, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vu...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Aug 5, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory. |
4Debian NetappNettle Project+1 more4Debian Linux Enterprise LinuxNettle+1 moreJun 17, 2026 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service. |
An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-R...Show more |
7Debian FedoraprojectHaxx+4 more33Cloud Backup Clustered Data OntapDebian Linux+30 moreJun 17, 2026 Aug 5, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into ac...Show more |
A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to insufficient validation of the parameter of...Show more |
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process. |
1Cisco 1Small Business Rv Series Router Firmware Jun 17, 2026 Aug 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the unde...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Aug 3, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link. |
1Huawei 1Oxfords An00a Firmware Jun 17, 2026 Aug 3, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The app can modify specific parameters, ca...Show more |
2Argo Workflows Project Argoproj2Argo Workflows Argo WorkflowsJun 17, 2026 Aug 3, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression tem...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Aug 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS. |
In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic. |
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset. |
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause code injection. |
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause random address access. |