CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,836 vulnerabilities with CWE-20
CVE-2026-48203 CRITICAL
Apache Camel Solr - Server-Side Request Forgery via SolrParam Headers
CVSS 9.1
CVE-2026-46726 HIGH
Apache Camel Vertx Websocket - Server-Side Request Forgery via Query Parameters
CVSS 7.5
CVE-2026-46592 HIGH
Apache Camel CXF - SOAP Operation Redirection via Headers
CVSS 7.5
CVE-2026-46585 HIGH
Apache Camel Lucene 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 7.5
CVE-2026-46584 LOW
Apache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters
CVSS 3.7
CVE-2026-46457 HIGH
Apache Camel NATS - Camel Control Header Injection
CVSS 7.5
CVE-2026-46456 CRITICAL
Apache Camel AWS2-SQS - Camel Control Header Injection
CVSS 9.8
CVE-2026-46454 CRITICAL
Apache Camel CometD - Unauthenticated Camel Control Header Injection
CVSS 9.8
CVE-2026-46453 MEDIUM
Apache Camel 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-59509 CRITICAL
Unauthenticated arbitrary MongoDB collection read in cve-search
CVE-2026-14723 MEDIUM
AD-Security AD_Miner Cache analyse_cache.py request_a deserialization
CVSS 5.3
CVE-2026-14637 HIGH
kirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserialization
CVSS 8.2
CVE-2026-58292 HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-57985 HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 7.6
CVE-2026-22547 CRITICAL
Gitea repository creation accepts invalid field values
CVSS 9.1
CVE-2026-14631 MEDIUM
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
CVSS 5.3
CVE-2026-13341 HIGH
Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCP
CVSS 7.4
CVE-2026-54405 HIGH
Ubiquiti INC UniFi Network Application - Improper Input Validation
CVSS 7.5
CVE-2026-54402 CRITICAL
Ubiquiti INC UniFi OS Server - Improper Input Validation
CVSS 9.9
CVE-2026-50748 CRITICAL
Ubiquiti INC UniFi Access Application < 4.2.29 - Improper Input Validation
CVSS 9.9
CVE-2026-14429 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-14428 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-14414 MEDIUM
Google Chrome - Improper Input Validation
CVSS 5.3
CVE-2026-14412 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-14411 CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
Details
Vulnerabilities 12,836
Exploit Likelihood High