CWE-20
12,942 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,942)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not ne...Show more |
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-cra...Show more |
1Free 5Freebox Delta Firmware Freebox Mini FirmwareFreebox One Firmware+2 moreJun 17, 2026 Sep 16, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3. |
1Free 5Freebox Delta Firmware Freebox Mini FirmwareFreebox One Firmware+2 moreJun 17, 2026 Sep 16, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3. |
1Free 1Freebox Hd Firmware Jun 17, 2026 Sep 16, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 A DNS rebinding vulnerability in Freebox v5 before 1.5.29. |
CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields. |
A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance....Show more |
xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impa...Show more |
In Gallagher Command Centre v8.20 prior to v8.20.1093(MR2) it is possible to create Guard Tour events that when accessed via things like reporting cause clients to temporarily hang or disconnect. |
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository. |
1Microsoft 1Sql Server Reporting Services Jun 17, 2026 Sep 11, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 <p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability co...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Sep 11, 2020 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an atta...Show more |
1Huawei 13Berkeley L09 Firmware Bla A09 FirmwareBla Tl00b Firmware+10 moreJun 17, 2026 Sep 11, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions earlier than 8.0.0.163(...Show more |
1Philips 13Intellivue Mp2 Mp90 Firmware Intellivue Mx100 FirmwareIntellivue Mx400 Firmware+10 moreJun 17, 2026 Sep 11, 2020 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly vali...Show more |
apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is des...Show more |
1Node Fetch Project 1Node Fetch Jun 17, 2026 Sep 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process wou...Show more |
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users t...Show more |
1Silk V3 Decoder Project 1Silk V3 Decoder Jun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow. |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Sep 9, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Sep 9, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |