← Back
CWE-20

12,906 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,906)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Draw
Jgraph
2Draw.io Diagrams
Mxgraph
Jun 17, 2026
Jul 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is as...Show more
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.Show less
1Ivanti
1Connect Secure
Nov 21, 2024
Jun 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.
2Ivanti
Pulsesecure
2Connect Secure
Pulse Policy Secure
Nov 21, 2024
Jun 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.
1Odoo
1Odoo
Nov 21, 2024
Jun 28, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database...Show more
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.Show less
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
1Google
1Chrome
Jun 17, 2026
Jun 27, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extensio...Show more
Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.Show less
1Google
1Chrome
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Ex...Show more
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.Show less
1Google
1Chrome
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a crafted HTML page.
1Google
1Chrome
Nov 21, 2024
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
1Google
1Chrome
Nov 21, 2024
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Exten...Show more
Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.Show less
1Google
1Chrome
Nov 21, 2024
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
1Moodle
1Moodle
Jun 17, 2026
Jun 26, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
1Libming
1Libming
Jun 17, 2026
Jun 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.
1Uclouvain
1Openjpeg
Nov 21, 2024
Jun 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service...Show more
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).Show less
1Digitaldruid
1Hoteldruid
Jun 17, 2026
Jun 24, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as de...Show more
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id_transazione=1&numero_contratto=1&n_file=a query string to visualizza_contratto.php.Show less
1Bluestacks
1Bluestacks App Player
Jun 17, 2026
Jun 23, 2019
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.
1Stopzilla
1Antimalware
Nov 21, 2024
Jun 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000206F.
1Stopzilla
1Antimalware
Nov 21, 2024
Jun 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000206B.