CWE-20
12,941 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,941)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Solarwinds 1Serv U Ftp Server Jun 17, 2026 Jul 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path. |
3Debian FedoraprojectLibraw3Debian Linux FedoraLibrawJun 17, 2026 Jul 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength)...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraGuacamoleJun 17, 2026 Jul 2, 2020 N/A· v4 4.4 MEDIUM· v3 1.2 LOW· v2 Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in discl...Show more |
1Nexaweb 2Nexacro 14 Nexacro 17Jun 17, 2026 Jul 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be leveraged for code execu...Show more |
1Nexaweb 2Nexacro 14 Nexacro 17Jun 17, 2026 Jul 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for cod...Show more |
2Fedoraproject Github Flavored Markdown Project2Fedora Github Flavored MarkdownJun 17, 2026 Jul 1, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, cau...Show more |
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired. |
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), versio...Show more |
1Arswp 1Windows Cleanup Assistant Jun 17, 2026 Jun 30, 2020 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD...Show more |
1Arswp 1Windows Cleanup Assistant Jun 17, 2026 Jun 30, 2020 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCA...Show more |
A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbitrary code, because of a using the old version of MySQL. |
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful exploitation could lead to application-level denial-of-service (dos). |
1Jiangmin 1Jiangmin Antivirus Jun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220440. |
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Jun 23, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute re...Show more |
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary c...Show more |
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft...Show more |
1Redhat 1Cloudforms Management Engine Jun 17, 2026 Jun 22, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console...Show more |
1Bitdefender 1Total Security 2020 Jun 17, 2026 Jun 22, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process. This i...Show more |
1Qualcomm 30Apq8096au Firmware Apq8098 FirmwareKamorta Firmware+27 moreJun 17, 2026 Jun 22, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ80...Show more |
1Qualcomm 15Apq8053 Firmware Apq8096au FirmwareMdm9607 Firmware+12 moreJun 17, 2026 Jun 22, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon...Show more |