← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Ecryptfs
2Debian Linux
Ecryptfs Utils
Nov 21, 2024
Dec 20, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
1Backdropcms
1Backdrop Cms
Jun 17, 2026
Dec 19, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check...Show more
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be required to have the "Synchronize, import, and export configuration" permission, a permission that only trusted administrators should be given. Other measures in the product prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.Show less
1Intel
1Converged Security Management Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Active Management Technology Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user...Show more
Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
1Converged Security Management Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
2Dynamic Application Loader
Trusted Execution Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged us...Show more
Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.Show less
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to po...Show more
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.Show less
1Intel
1Active Management Technology Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
1Intel
1Active Management Technology Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to po...Show more
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.Show less
1Intel
1Active Management Technology Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information...Show more
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.Show less
1Intel
1Active Management Technology Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.
1Intel
1Converged Security Management Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.
1Intel
1Active Management Technology Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via a...Show more
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.Show less
1Abb
1Pb610 Panel Builder 600
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests...Show more
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.Show less
1Abb
1Pb610 Panel Builder 600
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file s...Show more
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.Show less
1Apple
1Mac Os X
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.
1Apple
1Mac Os X
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.