CWE-20
12,945 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,945)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fastify Reply From Project 1Fastify Reply From Jun 17, 2026 Mar 2, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In fastify-reply-from before version 4.0.2, by crafting a specific URL, it is possible to escape the p...Show more |
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Se...Show more |
In mobile_log_d, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for ex...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 Feb 24, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device....Show more |
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulne...Show more |
2Apache Fedoraproject2Fedora Xmlgraphics CommonsJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnera...Show more |
4Apache DebianFedoraproject+1 more22Agile Engineering Data Management Banking ApisBanking Digital Experience+19 moreJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the...Show more |
1Redhat 13scale Api Management Jun 17, 2026 Feb 23, 2021 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges in certain queries allowing a malicious authenticated user to submit a r...Show more |
2Linux Redhat3Enterprise Linux Linux KernelOpenshift Container PlatformJun 17, 2026 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set...Show more |
3Debian FedoraprojectMbsync Project4Debian Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 23, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Feb 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS int...Show more |
1Qualcomm 173Aqt1000 Firmware Pm3003a FirmwarePm6150 Firmware+170 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 519Apq8009 Firmware Apq8016 FirmwareApq8017 Firmware+516 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdrag...Show more |
1Qualcomm 393Apq8009 Firmware Apq8016 FirmwareApq8064au Firmware+390 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO...Show more |
1Qualcomm 229Aqt1000 Firmware Ar8035 FirmwarePm3003a Firmware+226 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdra...Show more |
A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitrary code. This vulnerability is due to insufficient input(server domain) validation. An attacker cou...Show more |
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cook...Show more |
1Intel 1Ethernet Network Adapter 700 Firmware Jun 17, 2026 Feb 17, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 7.3 may allow a privileged user to potentially enable denial of service via local access. |
1Intel 1Ethernet Network Adapter E810 Firmware Jun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service...Show more |
1Intel 2Ethernet Network Adapter X722 Da2 Firmware Ethernet Network Adapter X722 Da4 FirmwareJun 17, 2026 Feb 17, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in the firmware for Intel(R) 722 Ethernet Controllers before version 1.4.3 may allow a privileged user to potentially enable denial of service via local access. |