CWE-20
12,906 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,906)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang...Show more |
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 18, 2019 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyF...Show more |
Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network pac...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 18, 2019 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: create...Show more |
1Cisco 10Spa500ds Firmware Spa500s FirmwareSpa501g Firmware+7 moreJun 17, 2026 Jul 17, 2019 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to improper input validation in the device...Show more |
1Cisco 4Access Points Aironet 3700e FirmwareAironet 3700i Firmware+1 moreJun 17, 2026 Jul 17, 2019 N/A· v4 7.4 HIGH· v3 6.1 MEDIUM· v2 A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected...Show more |
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension. |
2Fedoraproject Nic2Fedora Knot ResolverJun 17, 2026 Jul 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using a...Show more |
2Fedoraproject Nic2Fedora Knot ResolverJun 17, 2026 Jul 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-existence answer. NXDOMAIN answer would get p...Show more |
1Hyland 1Perceptive Content Server Nov 21, 2024 Jul 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Denial of Service vulnerability in the ImageNow Server service in Hyland Perceptive Content Server before 7.1.5 allows an attacker to crash the service via a TCP connection. |
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently...Show more |
1Microsoft 2.net Framework Visual Studio 2017Jun 17, 2026 Jul 15, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context...Show more |
1Microsoft 2Office Office 365Jun 17, 2026 Jul 15, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or wr...Show more |
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'. |
1Microsoft 2Azure Devops Server Team Foundation ServerJun 17, 2026 Jul 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jul 15, 2019 N/A· v4 6.8 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. |
2Linaro Trustedfirmware2Op Tee Op TeeJun 17, 2026 Jul 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later. |
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may a...Show more |