The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,423 vulnerabilities with CWE-20
CVE-2026-8391
MEDIUM
Firefox < 150.0.3 - Memory Corruption in JavaScript Engine
CVSS 5.3
CVE-2026-45393
HIGH
Cribl Edge < 4.17.1 - Improper Input Validation
CVSS 7.8
CVE-2026-45392
HIGH
Cribl Stream < 4.17.1 - Improper Input Validation
CVSS 8.7
CVE-2026-45391
HIGH
Cribl Edge < 4.17.1 - Improper Input Validation
CVSS 7.8
CVE-2026-43899
CRITICAL
DeepChat < 1.0.4-beta.1 Markdown Links - Remote Code Execution
CVSS 9.6
CVE-2026-28936
HIGH
iOS/iPadOS <18.7.9, macOS <14.8.7, visionOS <26.5 - DoS via Malicious File
CVSS 7.5
CVE-2026-28917
MEDIUM
iOS and iPadOS < 18.7.9 and < 26.5 - Denial of Service via Malicious Web Content
CVSS 4.3
CVE-2026-28907
HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Content Security Policy Bypass via Malicious Web Content
CVSS 8.1
CVE-2026-28860
HIGH
iOS and iPadOS < 18.7.7 - Local Keychain State Modification via Improper Input Validation
CVSS 7.5
CVE-2026-44658
LOW
Zen Browser: RSS Live-Folder Item URLs Are Not Scheme-Restricted Before Trusted Tab Creation
CVSS 2.4
CVE-2026-43895
MEDIUM
jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
CVSS 4.4
CVE-2026-31251
HIGH
CosyVoice thru 6e01309 - Deserialization
CVSS 7.3
CVE-2026-42613
CRITICAL
Grav: Privilege Escalation via Missing Server-Side Validation of groups/access
CVSS 9.4
CVE-2026-34086
LOW
AbuseFilter misuses ::userCanBitfield, exposing access-controlled information
CVE-2026-42301
HIGH
Improper Input Validation leading to Improper Control of Generation of Code ('Code Injection') in pyp2spec
CVSS 7.8
CVE-2026-44337
MEDIUM
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
CVSS 6.3
CVE-2026-44336
CRITICAL
PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
CVSS 9.6
CVE-2026-43944
CRITICAL
electerm: dangerous code can be run through links or command line
CVSS 9.6
CVE-2026-42261
HIGH
PromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`
CVSS 7.1
CVE-2026-33844
CRITICAL
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVSS 9.0
CVE-2026-6973
HIGH
KEV
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-41654
HIGH
Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVSS 8.1
CVE-2026-33589
MEDIUM
Open Notebook File Upload - Path Traversal Arbitrary File Read
CVSS 6.5
CVE-2026-33588
HIGH
Open Notebook < 1.8.3 - Path Traversal via File Upload
CVSS 8.1
CVE-2026-33587
CRITICAL
Open Notebook Transformations - Server-Side Template Injection RCE
CVSS 10.0
Details
Vulnerabilities
12,423
Exploit Likelihood
High