← Back
CWE-20

12,904 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,904)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Mate 9 Pro Fimware
Jun 17, 2026
Jun 4, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due to the lack of input validation. An attacker tricks the user who has root privilege to install an ap...Show more
Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due to the lack of input validation. An attacker tricks the user who has root privilege to install an application on the smart phone, and the application can read some process information, which may cause sensitive information leak.Show less
1Nvidia
1Geforce Experience
Jun 17, 2026
May 31, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attacker with local system access can craft input that may not be properly validated. Such an attack may...Show more
NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attacker with local system access can craft input that may not be properly validated. Such an attack may lead to code execution, denial of service or information disclosure.Show less
1Gitlab
1Gitlab
Jun 17, 2026
May 29, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).
1Projectatomic
1Bubblewrap
Jun 17, 2026
May 29, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users...Show more
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.Show less
1Qualcomm
12Qcs605 Firmware
Sd 670 FirmwareSd 675 Firmware+9 more
Jun 17, 2026
May 24, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCS605, SD 675, SD 712 / SD 710...Show more
Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCS605, SD 675, SD 712 / SD 710 / SD 670, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SM7150, SXR1130Show less
2Google
Opensuse
3Backports
ChromeLeap
Jun 17, 2026
May 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
2Google
Opensuse
3Backports
ChromeLeap
Jun 17, 2026
May 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
2Google
Opensuse
3Backports
ChromeLeap
Jun 17, 2026
May 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
2Google
Opensuse
3Backports
ChromeLeap
Jun 17, 2026
May 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
2Google
Opensuse
3Backports
ChromeLeap
Jun 17, 2026
May 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page.
1Zohocorp
1Manageengine Applications Manager
Nov 21, 2024
May 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality b...Show more
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
1Comsenz
1Discuz
Nov 21, 2024
May 22, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.
1Valvesoftware
1Steam Client
Nov 21, 2024
May 20, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended web sites.
1Cybozu
1Garoon
Jun 17, 2026
May 17, 2019
N/A· v4
8.7 HIGH· v3
5.5 MEDIUM· v2
Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.
1Intel
1Driver & Support Assistant
Jun 17, 2026
May 17, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.
1Intel
1Nuc Kit Firmware
Jun 17, 2026
May 17, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.
1Intel
1I915 Firmware
Jun 17, 2026
May 17, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Graphics Driver
Jun 17, 2026
May 17, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable denial o...Show more
Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable denial of service via local access.Show less