The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,423 vulnerabilities with CWE-20
CVE-2026-20240
MEDIUM
Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
CVSS 6.5
CVE-2026-5946
HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-8959
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS 9.6
CVE-2026-31378
MEDIUM
Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution
CVSS 6.5
CVE-2026-28751
LOW
OpenHarmony filemanagement_storage_service <=v6.0 - Local Denial of Service
CVSS 3.3
CVE-2026-27891
HIGH
Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
CVSS 7.2
CVE-2026-45495
HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-45492
MEDIUM
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVSS 5.4
CVE-2026-20685
MEDIUM
Apple Private Cloud Compute Server Software < 5E290.3 - Improper Input Validation
CVSS 6.5
CVE-2026-8759
HIGH
xiandafu beetl SpELFunction SpELFunction.java expression language injection
CVSS 7.3
CVE-2026-8751
HIGH
h2oai h2o-3 JAR Model.java importBinaryModel deserialization
CVSS 7.3
CVE-2026-8735
MEDIUM
Oinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserialization
CVSS 6.3
CVE-2026-45317
MEDIUM
Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVSS 4.6
CVE-2026-42327
HIGH
rust-openssl: undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
CVE-2026-8579
LOW
Google Chrome < 148.0.7778.168 - Out of Bounds Memory Write in Skia via Crafted Print File
CVSS 3.1
CVE-2026-8538
MEDIUM
Google Chrome < 148.0.7778.168 - Denial of Service via GPU Input Validation
CVSS 5.3
CVE-2026-8536
LOW
Google Chrome < 148.0.7778.168 - Site Isolation Bypass via ReadingMode Input Validation
CVSS 3.1
CVE-2026-8528
MEDIUM
Google Chrome < 148.0.7778.168 - Site Isolation Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-8527
HIGH
Google Chrome < 148.0.7778.168 - Remote Code Execution via Downloads Input Validation
CVSS 8.8
CVE-2026-8516
MEDIUM
Google Chrome < 148.0.7778.168 - Information Disclosure via DataTransfer Input Validation
CVSS 5.3
CVE-2026-26062
MEDIUM
Fleet server may terminate unexpectedly when handling certain gRPC requests
CVSS 6.5
CVE-2026-44522
HIGH
Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code Execution
CVE-2026-20224
HIGH
Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability
CVSS 8.6
CVE-2026-44482
CRITICAL
soundcloud-rpc: Remote Code Execution via XSS in Track Title
CVSS 9.6
CVE-2026-44425
MEDIUM
ShellHub: Crash-DoS via field injection in filter and sort-by parameters
CVSS 5.4
Details
Vulnerabilities
12,423
Exploit Likelihood
High