CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Nov 12, 2019 N/A· v4 6.2 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'....Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulne...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Nov 12, 2019 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulne...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreJun 17, 2026 Nov 12, 2019 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulne...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 6.8 MEDIUM· v3 6.8 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 6.8 MEDIUM· v3 6.8 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Executio...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Nov 12, 2019 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Executio...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Nov 12, 2019 N/A· v4 6.8 MEDIUM· v3 6.8 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service...Show more |
2Debian Gargoyle Project2Debian Linux GargoyleNov 21, 2024 Nov 12, 2019 N/A· v4 4.8 MEDIUM· v3 4.4 MEDIUM· v2 If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a directory with a cracked...Show more |
3Debian GnomeRedhat3Debian Linux Enterprise LinuxGdk PixbufNov 21, 2024 Nov 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw |
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use . |
liboping 1.3.2 allows users reading arbitrary files upon the local system. |
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations. |
mod_ruid2 before 0.9.8 improperly handles file descriptors which allows remote attackers to bypass security using a CGI script to break out of the chroot. |
2Fedoraproject Redhat2Fedora TunedNov 21, 2024 Nov 8, 2019 N/A· v4 5.5 MEDIUM· v3 4.7 MEDIUM· v2 tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. |
2Debian Mantisbt2Debian Linux MantisbtNov 21, 2024 Nov 7, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". |
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters. |
syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot. |
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack. |