CWE-20
12,942 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,942)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 114Sf200 24 Firmware Sf200 24fp FirmwareSf200 24p Firmware+111 moreJun 17, 2026 Aug 26, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device....Show more |
2Debian Redhat2Ansible Debian LinuxJun 17, 2026 Aug 26, 2020 N/A· v4 7.3 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the re...Show more |
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system...Show more |
Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information. |
Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly. |
HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that...Show more |
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters th...Show more |
1Openrobotics 1Robot Operating System Jun 17, 2026 Aug 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creat...Show more |
1Cisco 2Webex Meetings Webex Meetings ServerJun 17, 2026 Aug 17, 2020 N/A· v4 4.1 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to i...Show more |
1Cisco 2Webex Meetings Webex Meetings ServerJun 17, 2026 Aug 17, 2020 N/A· v4 4.1 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to i...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 Aug 17, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. To expl...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 Aug 17, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affec...Show more |
1Cisco 114Sf200 24 Firmware Sf200 24fp FirmwareSf200 24p Firmware+111 moreJun 17, 2026 Aug 17, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device....Show more |
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replic...Show more |
In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Lengt...Show more |
Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network access. |
1Intel 8S2600bpbr Firmware S2600bpqr FirmwareS2600bpsr Firmware+5 moreJun 17, 2026 Aug 13, 2020 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 11Ac 3165 Firmware Ac 3168 FirmwareAc 7265 Firmware+8 moreJun 17, 2026 Aug 13, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 73Cd1c32gk Firmware Cd1c64gk FirmwareCd1p64gk Firmware+70 moreJun 17, 2026 Aug 13, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 18Compute Module Hns2600bp Firmware Compute Module Hns2600kp FirmwareCompute Module Hns2600tp Firmware+15 moreJun 17, 2026 Aug 13, 2020 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 Improper input validation for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access. |