CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,423 vulnerabilities with CWE-20
CVE-2026-20240 MEDIUM
Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
CVSS 6.5
CVE-2026-5946 HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-8959 CRITICAL
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS 9.6
CVE-2026-31378 MEDIUM
Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution
CVSS 6.5
CVE-2026-28751 LOW
OpenHarmony filemanagement_storage_service <=v6.0 - Local Denial of Service
CVSS 3.3
CVE-2026-27891 HIGH
Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
CVSS 7.2
CVE-2026-45495 HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-45492 MEDIUM
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVSS 5.4
CVE-2026-20685 MEDIUM
Apple Private Cloud Compute Server Software < 5E290.3 - Improper Input Validation
CVSS 6.5
CVE-2026-8759 HIGH
xiandafu beetl SpELFunction SpELFunction.java expression language injection
CVSS 7.3
CVE-2026-8751 HIGH
h2oai h2o-3 JAR Model.java importBinaryModel deserialization
CVSS 7.3
CVE-2026-8735 MEDIUM
Oinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserialization
CVSS 6.3
CVE-2026-45317 MEDIUM
Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVSS 4.6
CVE-2026-42327 HIGH
rust-openssl: undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
CVE-2026-8579 LOW
Google Chrome < 148.0.7778.168 - Out of Bounds Memory Write in Skia via Crafted Print File
CVSS 3.1
CVE-2026-8538 MEDIUM
Google Chrome < 148.0.7778.168 - Denial of Service via GPU Input Validation
CVSS 5.3
CVE-2026-8536 LOW
Google Chrome < 148.0.7778.168 - Site Isolation Bypass via ReadingMode Input Validation
CVSS 3.1
CVE-2026-8528 MEDIUM
Google Chrome < 148.0.7778.168 - Site Isolation Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-8527 HIGH
Google Chrome < 148.0.7778.168 - Remote Code Execution via Downloads Input Validation
CVSS 8.8
CVE-2026-8516 MEDIUM
Google Chrome < 148.0.7778.168 - Information Disclosure via DataTransfer Input Validation
CVSS 5.3
CVE-2026-26062 MEDIUM
Fleet server may terminate unexpectedly when handling certain gRPC requests
CVSS 6.5
CVE-2026-44522 HIGH
Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code Execution
CVE-2026-20224 HIGH
Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability
CVSS 8.6
CVE-2026-44482 CRITICAL
soundcloud-rpc: Remote Code Execution via XSS in Track Title
CVSS 9.6
CVE-2026-44425 MEDIUM
ShellHub: Crash-DoS via field injection in filter and sort-by parameters
CVSS 5.4
Details
Vulnerabilities 12,423
Exploit Likelihood High