CWE-20
12,944 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,944)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials i...Show more |
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code. |
The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack on the NIO 50 (all versions). |
1Huawei 6Nip6300 Firmware Nip6600 FirmwareSecospace Usg6300 Firmware+3 moreJun 17, 2026 Nov 13, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploi...Show more |
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access. |
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access. |
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via network access. |
Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 2Server Board S2600st Firmware Server Board S2600wf FirmwareJun 17, 2026 Nov 12, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 1Converged Security And Manageability Engine Jun 17, 2026 Nov 12, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access. |
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code exe...Show more |
1Intel 11Dual Band Wireless Ac 3165 Firmware Dual Band Wireless Ac 3168 FirmwareDual Band Wireless Ac 8260 Firmware+8 moreJun 17, 2026 Nov 12, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access. |
Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access. |
3Intel NetappSiemens137Cloud Backup Clustered Data OntapFas/aff Bios+134 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Qualcomm 28Qcm6125 Firmware Qcs410 FirmwareQcs603 Firmware+25 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM...Show more |
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS comman...Show more |
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an inf...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Nov 10, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user...Show more |
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additi...Show more |
1Json8 Merge Patch Project 1Json8 Merge Patch Jun 17, 2026 Nov 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor. |