← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
4Iphone Os
Mac Os XTvos+1 more
Jun 17, 2026
Dec 18, 2019
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be...Show more
An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to initiate a Dictation request without user authorization.Show less
1Apple
6Icloud
Iphone OsItunes+3 more
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content m...Show more
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may result in the disclosure of process memory.Show less
1Qualcomm
20Ipq4019 Firmware
Ipq8064 FirmwareIpq8074 Firmware+17 more
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Integer overflow to buffer overflow due to lack of validation of event arguments received from firmware. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more
Integer overflow to buffer overflow due to lack of validation of event arguments received from firmware. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, QCN7605, QCS405, QCS605, SDA845, SDM660, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130Show less
1Qualcomm
30Apq8009 Firmware
Apq8053 FirmwareApq8064 Firmware+27 more
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT...Show more
Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, APQ8064, APQ8096AU, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8939, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SDA660, SDM630, SDM636, SDM660, SDX20, SDX24Show less
2Docker
Opensuse
3Cs Engine
DockerOpensuse
Nov 21, 2024
Dec 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a...Show more
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.Show less
2Docker
Opensuse
3Cs Engine
DockerOpensuse
Nov 21, 2024
Dec 17, 2019
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or...Show more
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.Show less
1Intel
19Cd1iv128mk Firmware
Cd1m3128mk FirmwareCd1p64gk Firmware+16 more
Jun 17, 2026
Dec 16, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.
1Huawei
2View 20 Firmware
Y9 2019 Firmware
Jun 17, 2026
Dec 13, 2019
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDM...Show more
Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices to exploit this vulnerability. Successful exploit may cause an infinite loop and the device to reboot.Show less
1Siemens
1Xhq
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the application to behave in unexpected ways for legitimate users. Successful exploitat...Show more
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the application to behave in unexpected ways for legitimate users. Successful exploitation does not require for an attacker to be authenticated. A successful attack could allow the import of scripts or generation of malicious links. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Theforeman
1Foreman
Nov 21, 2024
Dec 11, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Foreman has improper input validation which could lead to partial Denial of Service
2Debian
Gnome
2Debian Linux
Orca
Nov 21, 2024
Dec 11, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Orca has arbitrary code execution due to insecure Python module load
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Dec 10, 2019
N/A· v4
8.2 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulne...Show more
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.Show less
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
6.0 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Dis...Show more
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.Show less
5Canonical
DebianFedoraproject+2 more
8Chrome
Debian LinuxEnterprise Linux Desktop+5 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
1Mozilla
1Firefox
Nov 21, 2024
Dec 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
1Pyrad Project
1Pyrad
Nov 21, 2024
Dec 9, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
1Google
1Android
Jun 17, 2026
Dec 6, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. U...Show more
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140632678Show less
1Qnap
1Qts
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
2Kubernetes
Redhat
4External Provisioner
External ResizerExternal Snapshotter+1 more
Jun 17, 2026
Dec 5, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2)...Show more
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.Show less