← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1F5
16Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+13 more
Jun 17, 2026
Nov 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerabl...Show more
The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack.Show less
2Debian
Gksu Polkit Project
2Debian Linux
Gksu Polkit
Nov 21, 2024
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.
2Intel
Netapp
5Cloud Backup
Data Availability ServicesGraphics Driver+2 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.
2Intel
Netapp
5Cloud Backup
Data Availability ServicesGraphics Driver+2 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.
8Canonical
DebianF5+5 more
778Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+775 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local acces...Show more
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.Show less
1Intel
7Ethernet 700 Series Software
Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
1Intel
7Ethernet 700 Series Software
Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
1Intel
1Software Guard Extensions Sdk
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
1Intel
1Baseboard Management Controller Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
1Intel
1Baseboard Management Controller Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure via network access.
1Intel
1Baseboard Management Controller Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
2Hpe
Intel
284Apollo 4200 Gen10 Server Firmware
Apollo 4200 Gen9 Server FirmwareAtom C2308 Firmware+281 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
8.2 HIGH· v3
4.6 MEDIUM· v2
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Inte...Show more
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.Show less
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Nov 13, 2019
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can c...Show more
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.Show less
1Google
1Android
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privilege with System execution privileges needed. User interaction is not need...Show more
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-80316910Show less
1Google
1Android
Jun 17, 2026
Nov 13, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges need...Show more
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139186193Show less
1Google
1Android
Jun 17, 2026
Nov 13, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...Show more
In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-138441555Show less
1Enghouse
1Web Chat
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their na...Show more
An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their name and e-mail address). This POST request can be modified to change the message as well as the end recipient of the message. The e-mail address will have the same domain name and user as the product allotted. This can be used in phishing campaigns against users on the same domain.Show less
1Huawei
3Mate Rs Firmware
P20 FirmwareP20 Pro Firmware
Jun 17, 2026
Nov 13, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E3...Show more
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The system does not perform a properly validation of certain input models, an attacker could trick the user to install a malicious application then craft a malformed model, successful exploit could allow the attacker to get and tamper certain output data information.Show less
3Cor Entertainment
DebianFedoraproject
3Alien Arena
Debian LinuxFedora
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.