CWE-20
12,861 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,861)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4Windows 10 Windows 8.1Windows Server 2012+1 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.8 MEDIUM· v3 6.3 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly valid...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2008+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.4 MEDIUM· v3 5.2 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V running on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability."...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2008+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.8 MEDIUM· v3 6.3 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly va...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2008+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.8 MEDIUM· v3 6.3 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly va...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2008+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.6 HIGH· v3 7.4 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2008+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.6 HIGH· v3 7.4 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code...Show more |
1Microsoft 4Windows 10 Windows 8.1Windows Server 2012+1 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.8 MEDIUM· v3 6.3 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on...Show more |
1Microsoft 4Windows 10 Windows 8.1Windows Server 2012+1 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.4 MEDIUM· v3 5.2 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V running on Windows 10, Windows 10 1511, Windows 10 1607, Windows 8.1, Windows Server 2012 R2, and Windows Server 2016 host server fails to properly validate...Show more |
1Microsoft 2Windows 8.1 Windows Server 2012May 13, 2026 Apr 12, 2017 N/A· v4 5.4 MEDIUM· v3 5.2 MEDIUM· v2 An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated us...Show more |
1Microsoft 2Windows 10 Windows Server 2016May 13, 2026 Apr 12, 2017 N/A· v4 4.4 MEDIUM· v3 3.5 LOW· v2 A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability." |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2008+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.6 HIGH· v3 7.4 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code...Show more |
1Microsoft 4Windows 10 Windows 8.1Windows Server 2012+1 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.6 HIGH· v3 7.4 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from an a...Show more |
In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector. |
In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for...Show more |
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript. |
1F5 1Big Ip Access Policy Manager May 13, 2026 Apr 11, 2017 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Service Provider (SP) connector, might allow traffic to be disrupted or fa...Show more |
The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via vectors related to undefined behavior, as demonstrated on 32-bit ARM sys...Show more |
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. |
elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. |