CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jetbrains 2Teamcity UpsourceJun 17, 2026 Oct 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands. |
1Qualcomm 27Msm8909w Firmware Msm8996au FirmwareQcs405 Firmware+24 moreJun 17, 2026 Sep 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Sna...Show more |
1Qualcomm 26Mdm9206 Firmware Mdm9607 FirmwareMsm8996au Firmware+23 moreJun 17, 2026 Sep 30, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto...Show more |
1Qualcomm 40Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+37 moreJun 17, 2026 Sep 30, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &...Show more |
Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call. |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for expl...Show more |
In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interac...Show more |
In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploit...Show more |
In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicConstraints field of intermediary certificates. This could lead to remote information disclosure with no...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploit...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation...Show more |