CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apple 4Iphone Os Mac Os XTvos+1 moreJun 17, 2026 Dec 18, 2019 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be...Show more |
1Apple 6Icloud Iphone OsItunes+3 moreJun 17, 2026 Dec 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content m...Show more |
1Qualcomm 20Ipq4019 Firmware Ipq8064 FirmwareIpq8074 Firmware+17 moreJun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer overflow to buffer overflow due to lack of validation of event arguments received from firmware. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more |
1Qualcomm 30Apq8009 Firmware Apq8053 FirmwareApq8064 Firmware+27 moreJun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT...Show more |
2Docker Opensuse3Cs Engine DockerOpensuseNov 21, 2024 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a...Show more |
2Docker Opensuse3Cs Engine DockerOpensuseNov 21, 2024 Dec 17, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or...Show more |
1Intel 19Cd1iv128mk Firmware Cd1m3128mk FirmwareCd1p64gk Firmware+16 moreJun 17, 2026 Dec 16, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access. |
1Huawei 2View 20 Firmware Y9 2019 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDM...Show more |
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the application to behave in unexpected ways for legitimate users. Successful exploitat...Show more |
Foreman has improper input validation which could lead to partial Denial of Service |
Orca has arbitrary code execution due to insecure Python module load |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Dec 10, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Dec 10, 2019 N/A· v4 8.2 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulne...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Dec 10, 2019 N/A· v4 6.0 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Dis...Show more |
5Canonical DebianFedoraproject+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreJun 17, 2026 Dec 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page. |
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. |
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294. |
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. U...Show more |
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions. |
2Kubernetes Redhat4External Provisioner External ResizerExternal Snapshotter+1 moreJun 17, 2026 Dec 5, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2)...Show more |