CWE-20
12,946 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,946)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 399Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+396 moreJun 17, 2026 Jun 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon...Show more |
1Qualcomm 287Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+284 moreJun 17, 2026 Jun 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its RoT memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snap...Show more |
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation. |
2Debian Vmware2Debian Linux RabbitmqJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending mali...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jun 4, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arb...Show more |
wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 and prior, a vulnerability exists that can cause a denial of service between users. If a user has an invalid assetID fo...Show more |
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI wi...Show more |
1Genivi 1Diagnostic Log And Trace Jun 17, 2026 May 28, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to...Show more |
2Fedoraproject Uninett2Fedora RadsecproxyJun 17, 2026 May 28, 2021 N/A· v4 9.4 CRITICAL· v3 7.5 HIGH· v2 radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` scripts can lead to configuration injec...Show more |
In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing message validation in libra...Show more |
3Debian FedoraprojectSquid Cache3Debian Linux FedoraSquidJun 17, 2026 May 28, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP...Show more |
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript cod...Show more |
4Debian GaleraclusterMariadb+1 more4Debian Linux Galera Cluster For MysqlMariadb+1 moreJun 17, 2026 May 27, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera c...Show more |
1Huawei 2S5700 Firmware S6700 FirmwareJun 17, 2026 May 27, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 There is a denial of service vulnerability in the verisions V200R005C00SPC500 of S5700 and V200R005C00SPC500 of S6700. An attacker could exploit this vulnerability by sending specific message to a targeted device. Due to...Show more |
There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insufficient, an attacker can exploit this vulnerability to upload any files to the device. Successful exploi...Show more |
3Fedoraproject RedhatUpx3Enterprise Linux FedoraUpxJun 17, 2026 May 27, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file. |
3Eclipse OracleQuarkus4Communications Cloud Native Core Policy Jakarta Expression LanguageQuarkus+1 moreJun 17, 2026 May 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. |
3Fedoraproject GnomeRedhat4Enterprise Linux FedoraNetworkmanager+1 moreJun 17, 2026 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability. |
1Schneider Electric 2Modicon M241 Firmware Modicon M251 FirmwareJun 17, 2026 May 26, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP. |
1Vmware 2Cloud Foundation Vcenter ServerAug 12, 2026 May 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with netw...Show more |