← Back
CWE-20

12,884 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,884)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Maxpcsecure
1Anti Virus
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCt...Show more
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220009.Show less
1Maxpcsecure
1Anti Virus
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x22...Show more
In Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.Show less
1Escanav
1Anti Virus
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002...Show more
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C.Show less
1Escanav
1Anti Virus
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002...Show more
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8.Show less
1Escanav
1Anti Virus
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002...Show more
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4.Show less
1Redhat
2Jboss Enterprise Application Platform
Jboss Wildfly Application Server
Nov 21, 2024
Jan 24, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local file...Show more
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.Show less
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
1Apache
1Nifi
Nov 21, 2024
Jan 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0...Show more
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.Show less
1Apache
1Nifi
Nov 21, 2024
Jan 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0...Show more
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.Show less
1Hp
173A2w75a Firmware
A2w76a FirmwareA2w77a Firmware+170 more
Nov 21, 2024
Jan 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP OfficeJet Enterprise print...Show more
Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP OfficeJet Enterprise printers before 2308937_578479, 2405087_018548, and other firmware versions.Show less
3Canonical
DebianNlnetlabs
3Debian Linux
Ubuntu LinuxUnbound
Nov 21, 2024
Jan 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcar...Show more
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.Show less