CWE-20
12,904 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,904)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due to the lack of input validation. An attacker tricks the user who has root privilege to install an ap...Show more |
NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attacker with local system access can craft input that may not be properly validated. Such an attack may...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5). |
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users...Show more |
1Qualcomm 12Qcs605 Firmware Sd 670 FirmwareSd 675 Firmware+9 moreJun 17, 2026 May 24, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCS605, SD 675, SD 712 / SD 710...Show more |
2Google Opensuse3Backports ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
2Google Opensuse3Backports ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
2Google Opensuse3Backports ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
2Google Opensuse3Backports ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
2Google Opensuse3Backports ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page. |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 May 23, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality b...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. |
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code. |
1Valvesoftware 1Steam Client Nov 21, 2024 May 20, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended web sites. |
Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors. |
1Intel 1Driver & Support Assistant Jun 17, 2026 May 17, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access. |
Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access. |
Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable denial o...Show more |