CWE-20
12,946 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,946)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Insyde Siemens17Insydeh2o Ruggedcom Apr1808 FirmwareSimatic Field Pg M5 Firmware+14 moreAug 11, 2026 Jun 16, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for...Show more |
1Siemens 3Sinamics Sl150 Firmware Sinamics Sm150 FirmwareSinamics Sm150i FirmwareJun 17, 2026 Jun 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service condition, and/or executi...Show more |
1Hitachienergy 9Fox615 Tego1 Firmware Gms600 FirmwareModular Switchgear Monitoring Firmware+6 moreJun 17, 2026 Jun 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an atta...Show more |
1Dell 31Poweredge C4140 Firmware Poweredge C6420 FirmwarePoweredge C6525 Firmware+28 moreJun 17, 2026 Jun 14, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a den...Show more |
1Amd 2Radeon Pro Software Radeon SoftwareJun 17, 2026 Jun 11, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel, leading to escalation of privilege or denial of service. |
1Amd 2Radeon Pro Software Radeon SoftwareJun 17, 2026 Jun 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. |
In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This could lead to local escalation of privilege with no additional execution...Show more |
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privil...Show more |
1Schneider Electric 2Powerlogic Egx100 Firmware Powerlogic Egx300 FirmwareJun 17, 2026 Jun 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially cr...Show more |
1Schneider Electric 2Powerlogic Egx100 Firmware Powerlogic Egx300 FirmwareJun 17, 2026 Jun 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially cr...Show more |
1Schneider Electric 2Powerlogic Egx100 Firmware Powerlogic Egx300 FirmwareJun 17, 2026 Jun 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafted HTTP packet |
1Schneider Electric 2Powerlogic Egx100 Firmware Powerlogic Egx300 FirmwareJun 17, 2026 Jun 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially cr...Show more |
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area. |
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable. |
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege. |
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege. |
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory. |
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege. |
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action. |
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO. |