CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Ecryptfs2Debian Linux Ecryptfs UtilsNov 21, 2024 Dec 20, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation |
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check...Show more |
1Intel 1Converged Security Management Engine Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access. |
1Intel 2Converged Security Management Engine Firmware Trusted Execution Engine FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user...Show more |
1Intel 1Converged Security Management Engine Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 2Dynamic Application Loader Trusted Execution Engine FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged us...Show more |
1Intel 2Converged Security Management Engine Firmware Trusted Execution Engine FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to po...Show more |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access. |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. |
1Intel 2Converged Security Management Engine Firmware Trusted Execution Engine FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to po...Show more |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. |
1Intel 2Converged Security Management Engine Firmware Trusted Execution Engine FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information...Show more |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access. |
1Intel 1Converged Security Management Engine Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access. |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via a...Show more |
1Abb 1Pb610 Panel Builder 600 Jun 17, 2026 Dec 18, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests...Show more |
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file s...Show more |
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory. |
A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges. |