CWE-20
12,861 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,861)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Linux2Android Linux KernelMay 13, 2026 May 12, 2017 N/A· v4 7.0 HIGH· v3 7.6 HIGH· v2 An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High bec...Show more |
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue i...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 May 12, 2017 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 13, 2026 May 12, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 13, 2026 May 12, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2...Show more |
1Microsoft 18Asp.net Model View Controller Microsoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorer+15 moreMay 13, 2026 May 12, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. |
1Microsoft 18Asp.net Model View Controller Microsoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorer+15 moreMay 13, 2026 May 12, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. |
1Microsoft 18Asp.net Model View Controller Microsoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorer+15 moreMay 13, 2026 May 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function i...Show more |
1Microsoft 2Edge Internet ExplorerMay 13, 2026 May 12, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability." |
1Microsoft 2Windows 10 Windows Server 2016May 13, 2026 May 12, 2017 N/A· v4 7.6 HIGH· v3 5.4 MEDIUM· v2 Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation...Show more |
1Microsoft 3Windows Server 2008 Windows Server 2012Windows Server 2016May 13, 2026 May 12, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 are configured to answer version queries, aka "Windo...Show more |
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check that the current version...Show more |
1F5 10Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+7 moreMay 13, 2026 May 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from...Show more |
1Siemens 3Simatic Wincc Simatic Wincc (tia Portal)Simatic Wincc RuntimeMay 13, 2026 May 11, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Professional (V13 befor...Show more |
1Siemens 16Pcs 7 Primary Setup ToolSecurity Configuration Tool+13 moreMay 13, 2026 May 11, 2017 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS 7 V8.1 (All versions...Show more |
The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file. |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where it may access paged memory while holding a spinlock, leading to a denial of service. |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where a call to certain function requiring lower IRQL can be made under raised IRQL which m...Show more |
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service |
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead...Show more |