CWE-20
12,945 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,945)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve...Show more |
1Adobe 1Creative Cloud Desktop Application Jun 17, 2026 Mar 12, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an attacker to call functions against the installer to perform high privileged...Show more |
In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation. This could lead to a local bypass of defense in depth protections with no additional execution...Show more |
Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution. |
An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to c...Show more |
2Debian Privoxy2Debian Linux PrivoxyJun 17, 2026 Mar 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off. |
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison...Show more |
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vu...Show more |
Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an attacker needs to have TCP connectivity to t...Show more |
1Secomea 1Gatemanager Firmware Jun 17, 2026 Mar 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to...Show more |
Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corrupt EL2 memory. |
Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region. |
Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent denial of service. |
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager. |
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An...Show more |
2Fedoraproject Slic3r2Fedora Libslic3rJun 17, 2026 Mar 3, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosur...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation c...Show more |
1Fastify Http Proxy Project 1Fastify Http Proxy Jun 17, 2026 Mar 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific URL, it is possible to escape the prefix of the proxied backend service...Show more |