CWE-20
12,906 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,906)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 3Compute Card Firmware Compute Stick FirmwareNuc Kit FirmwareJun 17, 2026 Jun 13, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. |
1Intel 3Compute Card Firmware Compute Stick FirmwareNuc Kit FirmwareJun 17, 2026 Jun 13, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient session validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. |
1Intel 2Software Guard Extensions Software Guard Extensions Data Center Attestation PrimitivesJun 17, 2026 Jun 13, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in the Intel(R) SGX driver for Linux may allow an authenticated user to potentially enable a denial of service via local access. |
1Intel 3Converged Security Management Engine Firmware Server Platform Services FirmwareTrusted Execution Engine FirmwareNov 21, 2024 Jun 13, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jun 12, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jun 12, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jun 12, 2019 N/A· v4 6.8 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already...Show more |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Jun 12, 2019 N/A· v4 6.8 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already...Show more |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Jun 12, 2019 N/A· v4 6.8 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Jun 12, 2019 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could...Show more |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Jun 12, 2019 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could...Show more |
1Solarwinds 1Dameware Mini Remote Control Jun 17, 2026 Jun 7, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the applica...Show more |
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key negotiation, which could crash the applicat...Show more |
1Dell 1Emc Openmanage Server Administrator Jun 17, 2026 Jun 6, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of...Show more |
An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any user with REPORTER access or above is able to view any private issue's d...Show more |
1Cisco 1Industrial Network Director Jun 17, 2026 Jun 5, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files upload...Show more |
1Cisco 2Telepresence Video Communication Server Unified Communications Manager Im And Presence ServiceJun 17, 2026 Jun 5, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series co...Show more |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A remote code exection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |