CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 3Roomos Telepresence CodecTelepresence Collaboration EndpointJun 17, 2026 Nov 26, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestrict...Show more |
1Cisco 1Wireless Lan Controller Software Jun 17, 2026 Nov 26, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerab...Show more |
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations. |
Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. |
Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. |
Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page. |
Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. |
Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
2Google Opensuse2Backports ChromeJun 17, 2026 Nov 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application. |
Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page. |
Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page. |
opendnssec misuses libcurl API |
1Qualcomm 12Apq8053 Firmware Apq8096au FirmwareMsm8996au Firmware+9 moreJun 17, 2026 Nov 21, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snap...Show more |
1Qualcomm 13Apq8053 Firmware Apq8096au FirmwareApq8098 Firmware+10 moreJun 17, 2026 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectiv...Show more |
Gamera before 3.4.1 insecurely creates temporary files. |
2Debian Rc Project2Debian Linux RcNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 rc before 1.7.1-5 insecurely creates temporary files. |
29base Project Debian29base Debian LinuxNov 21, 2024 Nov 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. |
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly. |
2Fedoraproject Sillycycle2Fedora XlockmoreNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xlockmore before 5.43 'dclock' security bypass vulnerability |
cumin: At installation postgresql database user created without password |