← Back
CWE-20

12,941 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,941)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
1Serv U Ftp Server
Jun 17, 2026
Jul 5, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
3Debian
FedoraprojectLibraw
3Debian Linux
FedoraLibraw
Jun 17, 2026
Jul 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength)...Show more
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.Show less
3Apache
DebianFedoraproject
3Debian Linux
FedoraGuacamole
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.4 MEDIUM· v3
1.2 LOW· v2
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in discl...Show more
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.Show less
1Nexaweb
2Nexacro 14
Nexacro 17
Jun 17, 2026
Jul 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be leveraged for code execu...Show more
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be leveraged for code execution by rebooting the victim’s PCShow less
1Nexaweb
2Nexacro 14
Nexacro 17
Jun 17, 2026
Jul 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for cod...Show more
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for code execution by rebooting the victim’s PCShow less
2Fedoraproject
Github Flavored Markdown Project
2Fedora
Github Flavored Markdown
Jun 17, 2026
Jul 1, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, cau...Show more
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been fixed in version 0.29.0.gfm.1.Show less
1Sap
1Solution Manager
Jun 17, 2026
Jul 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.
1Nvidia
1Virtual Gpu Manager
Jun 17, 2026
Jun 30, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), versio...Show more
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).Show less
1Arswp
1Windows Cleanup Assistant
Jun 17, 2026
Jun 30, 2020
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD...Show more
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD.Show less
1Arswp
1Windows Cleanup Assistant
Jun 17, 2026
Jun 30, 2020
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCA...Show more
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCA.Show less
1Commax
1Cdp 1020mb Firmware
Jun 17, 2026
Jun 30, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbitrary code, because of a using the old version of MySQL.
1Adobe
1Coldfusion
Jun 17, 2026
Jun 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful exploitation could lead to application-level denial-of-service (dos).
1Jiangmin
1Jiangmin Antivirus
Jun 17, 2026
Jun 26, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220440.
1Rockwellautomation
1Factorytalk Services Platform
Jun 17, 2026
Jun 23, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute re...Show more
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.Show less
1Freedroid
1Freedroidrpg
Jun 17, 2026
Jun 23, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary c...Show more
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.Show less
1Redhat
1Keycloak
Jun 17, 2026
Jun 22, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft...Show more
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.Show less
1Redhat
1Cloudforms Management Engine
Jun 17, 2026
Jun 22, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console...Show more
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on the CloudForms server as root.Show less
1Bitdefender
1Total Security 2020
Jun 17, 2026
Jun 22, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process. This i...Show more
Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process. This issue affects Bitdefender Total Security 2020 versions prior to 24.0.20.116.Show less
1Qualcomm
30Apq8096au Firmware
Apq8098 FirmwareKamorta Firmware+27 more
Jun 17, 2026
Jun 22, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ80...Show more
Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ8098, Kamorta, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130Show less
1Qualcomm
15Apq8053 Firmware
Apq8096au FirmwareMdm9607 Firmware+12 more
Jun 17, 2026
Jun 22, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon...Show more
While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8096AU, MDM9607, MSM8909W, MSM8996, MSM8996AU, QCN7605, QCS605, SC8180X, SDA845, SDX20, SDX24, SDX55, SM8150, SXR1130Show less