CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,423 vulnerabilities with CWE-20
CVE-2026-7945 LOW
Google Chrome < 148.0.7778.96 - Site Isolation Bypass via COOP Input Validation
CVSS 3.1
CVE-2026-7944 LOW
Google Chrome < 148.0.7778.96 - Site Isolation Bypass via Persistent Cache Input Validation
CVSS 3.1
CVE-2026-7943 MEDIUM
Google Chrome < 148.0.7778.96 - Arbitrary Read/Write via ANGLE Input Validation
CVSS 4.2
CVE-2026-7941 MEDIUM
Google Chrome < 148.0.7778.96 - Universal Cross-Site Scripting via Crafted Extension
CVSS 4.4
CVE-2026-7934 MEDIUM
Google Chrome < 148.0.7778.96 - Navigation Restriction Bypass via Popup Blocker Input Validation
CVSS 4.2
CVE-2026-7931 MEDIUM
Google Chrome < 148.0.7778.96 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2026-7916 HIGH
Google Chrome < 148.0.7778.96 - Sandbox Escape via InterestGroups
CVSS 8.3
CVE-2026-7915 MEDIUM
Google Chrome <148.0.7778.96 - Auth Bypass
CVSS 4.3
CVE-2026-7905 HIGH
Google Chrome < 148.0.7778.96 - Sandbox Escape via Media Input Validation
CVSS 8.3
CVE-2026-40068 HIGH
Claude Code arbitrary code execution via git worktree commondir trust dialog bypass
CVSS 8.8
CVE-2026-32603 MEDIUM
Sandboxie kernel driver denial of service via malformed IOCTL from sandboxed process
CVSS 6.5
CVE-2026-6180 HIGH
PaperCut MF: Card truncation on HP readers
CVSS 8.1
CVE-2026-42812 CRITICAL
Apache Polaris: No protection on `write.metadata.path`
CVSS 9.9
CVE-2026-42811 CRITICAL
Apache Polaris: could broaden vended GCS credentials through unescaped identifier content in access-boundary CEL conditions
CVSS 9.9
CVE-2026-42810 CRITICAL
Apache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or table names
CVSS 9.9
CVE-2026-42809 CRITICAL
Apache Polaris: staged table creation could vend storage credentials for unvalidated locations
CVSS 9.9
CVE-2026-37458 MEDIUM
FRRouting 10.0-10.6 - Authenticated Denial of Service via MP_REACH_NLRI UPDATE Message
CVSS 6.5
CVE-2026-7712 MEDIUM
MindsDB Pickle pickle.loads deserialization
CVSS 6.3
CVE-2026-7597 MEDIUM
mem0ai mem0 faiss.py pickle.dump deserialization
CVSS 6.3
CVE-2026-1577 MEDIUM
IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries
CVSS 6.5
CVE-2026-5174 HIGH
Improper Access Control Vulnerability in Progress MOVEit Automation
CVSS 7.7
CVE-2026-1858 MEDIUM
wget2 Improper Certificate Validation
CVSS 4.8
CVE-2026-30769 HIGH
EnTech Taiwan TVicPort 4.0 - Privilege Escalation
CVSS 7.8
CVE-2026-7360 LOW
Google Chrome <147.0.7727.138 - Site Isolation Bypass
CVSS 3.1
CVE-2026-7345 HIGH
Google Chrome <147.0.7727.138 - Sandbox Escape
CVSS 8.3
Details
Vulnerabilities 12,423
Exploit Likelihood High