CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,423 vulnerabilities with CWE-20
CVE-2026-8391 MEDIUM
Firefox < 150.0.3 - Memory Corruption in JavaScript Engine
CVSS 5.3
CVE-2026-45393 HIGH
Cribl Edge < 4.17.1 - Improper Input Validation
CVSS 7.8
CVE-2026-45392 HIGH
Cribl Stream < 4.17.1 - Improper Input Validation
CVSS 8.7
CVE-2026-45391 HIGH
Cribl Edge < 4.17.1 - Improper Input Validation
CVSS 7.8
CVE-2026-43899 CRITICAL
DeepChat < 1.0.4-beta.1 Markdown Links - Remote Code Execution
CVSS 9.6
CVE-2026-28936 HIGH
iOS/iPadOS <18.7.9, macOS <14.8.7, visionOS <26.5 - DoS via Malicious File
CVSS 7.5
CVE-2026-28917 MEDIUM
iOS and iPadOS < 18.7.9 and < 26.5 - Denial of Service via Malicious Web Content
CVSS 4.3
CVE-2026-28907 HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Content Security Policy Bypass via Malicious Web Content
CVSS 8.1
CVE-2026-28860 HIGH
iOS and iPadOS < 18.7.7 - Local Keychain State Modification via Improper Input Validation
CVSS 7.5
CVE-2026-44658 LOW
Zen Browser: RSS Live-Folder Item URLs Are Not Scheme-Restricted Before Trusted Tab Creation
CVSS 2.4
CVE-2026-43895 MEDIUM
jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
CVSS 4.4
CVE-2026-31251 HIGH
CosyVoice thru 6e01309 - Deserialization
CVSS 7.3
CVE-2026-42613 CRITICAL
Grav: Privilege Escalation via Missing Server-Side Validation of groups/access
CVSS 9.4
CVE-2026-34086 LOW
AbuseFilter misuses ::userCanBitfield, exposing access-controlled information
CVE-2026-42301 HIGH
Improper Input Validation leading to Improper Control of Generation of Code ('Code Injection') in pyp2spec
CVSS 7.8
CVE-2026-44337 MEDIUM
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
CVSS 6.3
CVE-2026-44336 CRITICAL
PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
CVSS 9.6
CVE-2026-43944 CRITICAL
electerm: dangerous code can be run through links or command line
CVSS 9.6
CVE-2026-42261 HIGH
PromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`
CVSS 7.1
CVE-2026-33844 CRITICAL
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVSS 9.0
CVE-2026-6973 HIGH KEV
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-41654 HIGH
Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVSS 8.1
CVE-2026-33589 MEDIUM
Open Notebook File Upload - Path Traversal Arbitrary File Read
CVSS 6.5
CVE-2026-33588 HIGH
Open Notebook < 1.8.3 - Path Traversal via File Upload
CVSS 8.1
CVE-2026-33587 CRITICAL
Open Notebook Transformations - Server-Side Template Injection RCE
CVSS 10.0
Details
Vulnerabilities 12,423
Exploit Likelihood High