CWE-20
12,942 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,942)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. An attacker in a privil...Show more |
A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. Processing a maliciously crafted image may lead to a denial of service. |
A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra. A sandboxed process may be able to circumvent sand...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreJun 17, 2026 Oct 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3, watchOS 5.3. An...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreJun 17, 2026 Oct 27, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, tvOS 12.3, watchOS 5.2.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Updat...Show more |
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. An application may be able to gai...Show more |
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, watchOS 5.2.1. A remot...Show more |
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 20...Show more |
3Mozilla NetappSiemens13Hci Compute Node Hci Management NodeHci Storage Node+10 moreJun 17, 2026 Oct 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result...Show more |
1Apple 4Ipados Iphone OsMac Os X+1 moreJun 17, 2026 Oct 22, 2020 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A remote attacker may be able to cause unexpected system ter...Show more |
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to determine kernel memory layout. |
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges. |
1Cisco 2Firepower Threat Defense Secure Firewall Threat DefenseAug 11, 2026 Oct 21, 2020 N/A· v4 7.4 HIGH· v3 6.1 MEDIUM· v2 A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Threat DefenseAug 11, 2026 Oct 21, 2020 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Threat DefenseAug 11, 2026 Oct 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input va...Show more |
1Cisco 4Adaptive Security Appliance Adaptive Security Appliance SoftwareFirepower Threat Defense+1 moreAug 11, 2026 Oct 21, 2020 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload u...Show more |
1Sap 1Netweaver Compare Systems Jun 17, 2026 Oct 20, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS leve...Show more |
1Object Path Project 1Object Path Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be...Show more |
2Fedoraproject Yubico2Fedora Yubihsm ShellJun 17, 2026 Oct 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized m...Show more |
1Sprecher Automation 1Sprecon E Jun 17, 2026 Oct 19, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks the validation of the input values on the device side, which is provide...Show more |