← Back
CWE-20

12,894 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,894)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Dec 11, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Dec 11, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Nov 21, 2024
Dec 11, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTM...Show more
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.Show less
1Ibm
2Datapower Gateway
Mq Appliance
Nov 21, 2024
Dec 11, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0...Show more
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.Show less
1Qacctv
1Jooan Ja Q1h Wi Fi Camera Firmware
Nov 21, 2024
Dec 10, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetSt...Show more
Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on.Show less
1Libav
1Libav
Nov 21, 2024
Dec 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in libavcodec/apedec.c that will lead to remote denial of service via crafted input.
1Anker
2Nebula Capsule Projector
Nebula Capsule Projector Firmware
Nov 21, 2024
Dec 8, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operating system) via a crafted application that sends data to WifiService.
2Debian
Xen
2Debian Linux
Xen
Nov 21, 2024
Dec 8, 2018
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions as...Show more
An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.Show less
1Onionshare
1Onionshare
Nov 21, 2024
Dec 7, 2018
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive i...Show more
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.Show less
1Amazon
1Amazon Web Services Freertos
Nov 21, 2024
Dec 6, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGD_SecureConnect_Connect in AWS TLS connectivity...Show more
Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGD_SecureConnect_Connect in AWS TLS connectivity modules.Show less
1Google
1Android
Jun 17, 2026
Dec 6, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed....Show more
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-114223584.Show less
1Ibm
1I2 Enterprise Insight Analysis
Nov 21, 2024
Dec 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability...Show more
IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 141340.Show less
1Nuuo
1Nvrmini2 Firmware
Nov 21, 2024
Dec 5, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the d...Show more
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.Show less
1Google
1Chrome
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate setting of the SEE_MASK_FLAG_NO_UI flag in file downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially bypass OS malware checks via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML pag...Show more
A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.Show less
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
2Fedoraproject
Gnu
2Fedora
Glibc
Dec 3, 2025
Dec 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex(...Show more
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.Show less
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demons...Show more
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.Show less