CWE-20
12,946 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,946)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause an infinite loop in DoS. |
In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to...Show more |
1Emerson 1Proficy Machine Edition Jun 17, 2026 Jul 30, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the comp...Show more |
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU. |
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_SIZE File Contents Request PDU. |
1Trendmicro 4Apex One OfficescanOfficescan Business Security+1 moreJun 17, 2026 Jul 29, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations....Show more |
In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. |
1Archisteamfarm Project 1Archisteamfarm Jun 17, 2026 Jul 26, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In versions prior to 4.3.1.0 a Denial of Service (aka DoS) vulnerability which allows attacker to remot...Show more |
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 202771. |
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it improperly validates the length field in a request from a guest. This flaw allows a malicious guest to send a length field...Show more |
When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper input validation |
1Dell 2Emc Openmanage Enterprise Emc Openmanage Enterprise ModularJun 17, 2026 Jul 19, 2021 N/A· v4 7.6 HIGH· v3 5.5 MEDIUM· v2 Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an improper input validation vulnerability. A remote authenticated malicious user wit...Show more |
1Ibm 1Resilient Security Orchestration Automation And Response Jun 17, 2026 Jul 19, 2021 N/A· v4 4.7 MEDIUM· v3 6.5 MEDIUM· v2 IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should not have access to due to improper input validation. IBM X-Force ID: 203085. |
NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function. |
A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets...Show more |
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:...Show more |
1Ibm 1Security Verify Access Jun 17, 2026 Jul 15, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreAug 10, 2026 Jul 14, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Win32k Elevation of Privilege Vulnerability |
In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution...Show more |