CWE-20
12,946 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,946)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Remote Denial of Service in LwM2M do_write_op_tlv. Zephyr versions >= 1.14.2, >= 2.2.0 contain Improper Input Validation (CWE-20), Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835). For more information, s...Show more |
4Debian NetappRedhat+1 more4Debian Linux Enterprise LinuxLibwebp+1 moreJun 17, 2026 May 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. |
2Fedoraproject Redhat3Ceph Ceph StorageFedoraJun 17, 2026 May 18, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The g...Show more |
3Debian FedoraprojectRedhat4Ceph Ceph StorageDebian Linux+1 moreJun 17, 2026 May 17, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in t...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 May 14, 2021 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerabi...Show more |
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based on a `CHECK`-failure. The implementation(https://github.com/tensorflow/...Show more |
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to inject inject malicious data using a specially crafted HTTP request due to improper input validation. |
1Mercedes Benz 1Mercedes Benz User Experience Jun 17, 2026 May 13, 2021 N/A· v4 6.8 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution. |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 May 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integr...Show more |
3Debian FedoraprojectLibrdf3Debian Linux FedoraRaptor Rdf Syntax LibraryJun 17, 2026 May 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 13, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat f...Show more |
1Beckhoff 3Ipc Diagnostics Ua Server Tf6100Twincat Opc Ua ServerJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send seve...Show more |
1Blackberry 1Unified Endpoint Management Jun 17, 2026 May 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentia...Show more |
3Arista SamsungSiemens19C 100 Firmware C 110 FirmwareC 120 Firmware+16 moreJun 17, 2026 May 11, 2021 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragm...Show more |
2Samsung Siemens136gk5763 1al00 3aa0 Firmware 6gk5763 1al00 3da0 Firmware6gk5763 1al00 7da0 Firmware+10 moreJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfrag...Show more |
3Arista SamsungSiemens18C 100 Firmware C 110 FirmwareC 120 Firmware+15 moreJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) he...Show more |
3Alfa AristaSiemens6Awus036h Firmware C 65 FirmwareC 75 Firmware+3 moreJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this...Show more |
Microsoft Exchange Server Remote Code Execution Vulnerability |
1Sap 1Netweaver Process Integration Jun 17, 2026 May 11, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicio...Show more |
Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code via crafted data. For example, a tape head may have an unexpected loca...Show more |