CWE-20
12,944 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,944)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dlink 10Dsr 1000 Firmware Dsr 1000ac FirmwareDsr 1000n Firmware+7 moreJun 17, 2026 Dec 15, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation...Show more |
1Dlink 10Dsr 1000 Firmware Dsr 1000ac FirmwareDsr 1000n Firmware+7 moreJun 17, 2026 Dec 15, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This...Show more |
1Hosteng 3H0 Ecom100 Firmware H2 Ecom100 FirmwareH4 Ecom100 FirmwareJun 17, 2026 Dec 15, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker t...Show more |
In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for expl...Show more |
In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed...Show more |
In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges neede...Show more |
An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid) doesn't check whether the header extension length field would overflo...Show more |
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the incoming DNS replies match outgoing DNS queries in newdata() in resolv.c...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Dec 11, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability coul...Show more |
1Ibm 1Resilient Security Orchestration Automation And Response Jun 17, 2026 Dec 11, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation. |
2Fedoraproject Jasper Project2Fedora JasperJun 17, 2026 Dec 11, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integr...Show more |
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields. |
In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a query-of-death vulnera...Show more |
AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local privilege escalation. |
1Apple 3Ipados Iphone OsMac Os XJun 17, 2026 Dec 8, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious...Show more |
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector. |
ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through so...Show more |
1Mitsubishielectric 19R00cpu Firmware R01cpu FirmwareR02cpu Firmware+16 moreJun 17, 2026 Nov 30, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Vali...Show more |
1Rockwellautomation 1Factorytalk Linx Jun 17, 2026 Nov 26, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a den...Show more |
Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains...Show more |