CWE-20
12,973 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,973)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridg...Show more |
Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-r...Show more |
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a de...Show more |
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a de...Show more |
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privilege...Show more |
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to by...Show more |
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is res...Show more |
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive fil...Show more |
1Netgear 4Mr70 Firmware Ms70 FirmwareRaxe500 Firmware+1 moreJun 18, 2026 Jun 9, 2026 6.9 MEDIUM· v4 8.1 HIGH· v3 N/A· v2 A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device. |
1Netgear 22Lbr1020 Firmware Lbr20 FirmwareR6700ax Firmware+19 moreJun 18, 2026 Jun 9, 2026 5.6 MEDIUM· v4 8.0 HIGH· v3 N/A· v2 Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations. |
1Netgear 4Cax30 Firmware Rax30 FirmwareRax5 Firmware+1 moreJun 18, 2026 Jun 9, 2026 5.2 MEDIUM· v4 8.8 HIGH· v3 N/A· v2 An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. |
1Netgear 31Ex3700 Firmware Ex3800 FirmwareEx6120 Firmware+28 moreJun 18, 2026 Jun 9, 2026 4.9 MEDIUM· v4 4.5 MEDIUM· v3 N/A· v2 Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. |
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_eve...Show more |
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packe...Show more |
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage t...Show more |
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage t...Show more |
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 3.9 LOW· v3 N/A· v2 Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |