← Back
CWE-20

12,941 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,941)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Npm Programmatic Project
1Npm Programmatic
Jun 17, 2026
Apr 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly.
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with L(5.0/5.1) (with USB OTG MyFile2014_L_ESS support) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5068 (June 2016).
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotected intent. The Samsung IDs are SVE-2016-7179 and SVE-2016-7182 (November...Show more
An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotected intent. The Samsung IDs are SVE-2016-7179 and SVE-2016-7182 (November 2016).Show less
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. AntService allows a system_server crash and reboot. The Samsung ID is SVE-2016-7044 (November 2016).
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with software through 2015-11-11 (supporting FRP/RL). There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5131 (January 2016).
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a malformed JPEG file. The Samsung ID is SVE-2015-5110 (January 2016).
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-5421 (March 2016).
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reach the radio layer (aka RIL or RILD) to place calls or send SMS messages...Show more
An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reach the radio layer (aka RIL or RILD) to place calls or send SMS messages. The Samsung ID is SVE-2016-5733 (May 2016).Show less
1Utils Extend Project
1Utils Extend
Jun 17, 2026
Apr 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.
1Fortinet
1Fortios
Nov 21, 2024
Apr 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution...Show more
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.Show less
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution...Show more
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.Show less
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution...Show more
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.Show less
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to leak memory.
1Sonatype
1Nexus
Jun 17, 2026
Apr 1, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
1Apple
1Mac Os X
Jun 17, 2026
Apr 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.