← Back
CWE-20

12,944 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,944)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Security Manager
Jun 17, 2026
Nov 17, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials i...Show more
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by viewing source code. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.Show less
1Nagios
1Nagios Xi
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
1Nexcom
1Nio 50 Firmware
Jun 17, 2026
Nov 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack on the NIO 50 (all versions).
1Huawei
6Nip6300 Firmware
Nip6600 FirmwareSecospace Usg6300 Firmware+3 more
Jun 17, 2026
Nov 13, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploi...Show more
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions include:NIP6300 versions V500R001C30,V500R001C60;NIP6600 versions V500R001C30,V500R001C60;Secospace USG6300 versions V500R001C30,V500R001C60;Secospace USG6500 versions V500R001C30,V500R001C60;Secospace USG6600 versions V500R001C30,V500R001C60;USG9500 versions V500R001C30,V500R001C60.Show less
1Intel
1Data Center Manager
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access.
1Intel
1Data Center Manager
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access.
1Intel
1Data Center Manager
Jun 17, 2026
Nov 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via network access.
1Intel
1Adas Ie
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
2Server Board S2600st Firmware
Server Board S2600wf Firmware
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Converged Security And Manageability Engine
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Nov 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code exe...Show more
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).Show less
1Intel
11Dual Band Wireless Ac 3165 Firmware
Dual Band Wireless Ac 3168 FirmwareDual Band Wireless Ac 8260 Firmware+8 more
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1Intel
1Proset/wireless Wifi
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
3Intel
NetappSiemens
137Cloud Backup
Clustered Data OntapFas/aff Bios+134 more
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
1Qualcomm
28Qcm6125 Firmware
Qcs410 FirmwareQcs603 Firmware+25 more
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM...Show more
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA845, SDM640, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150PShow less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS comman...Show more
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.Show less
1Freedesktop
1Accountsservice
Jun 17, 2026
Nov 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an inf...Show more
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Nov 10, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user...Show more
SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.Show less
1Google
1Android
Jun 17, 2026
Nov 10, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additi...Show more
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-147358092Show less
1Json8 Merge Patch Project
1Json8 Merge Patch
Jun 17, 2026
Nov 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.