The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,423 vulnerabilities with CWE-20
CVE-2026-7317
MEDIUM
Grav CMS Cache Value FileCache.php doGet deserialization
CVSS 5.0
CVE-2026-24204
MEDIUM
NVIDIA FLARE SDK < 2.7.2 - Path Traversal and Information Disclosure
CVSS 6.5
CVE-2026-5941
HIGH
Foxit PDF Editor/Reader AcroForm Signature Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-41044
HIGH
Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
CVSS 8.8
CVE-2026-40466
HIGH
Apache ActiveMQ Broker < 5.19.6 and 6.0.0 to before 6.2.5 - Remote Code Execution
CVSS 8.8
CVE-2026-41268
HIGH
Flowise: Flowise Parameter Override Bypass Remote Command Execution
CVSS 7.7
CVE-2026-34066
MEDIUM
nimiq-blockchain: Peer-triggerable panic during history sync
CVSS 5.3
CVE-2026-33471
CRITICAL
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
CVSS 9.6
CVE-2026-35380
MEDIUM
uutils coreutils cut Local Logic Error and Data Integrity Issue in Delimiter Parsing
CVSS 5.5
CVE-2026-35377
LOW
uutils coreutils env Local Denial of Service via Improper Handling of Backslashes in Split-String Mode
CVSS 3.3
CVE-2026-35369
MEDIUM
uutils coreutils kill System-wide Process Termination and Denial of Service via Argument Misinterpretation
CVSS 5.5
CVE-2026-35347
MEDIUM
uutils coreutils comm Silent Data Loss or Denial of Service via Improper Input Validation
CVSS 4.4
CVE-2026-31192
MEDIUM
Raindrop.io Bookmark Manager Web App 5.6.76.0 - Info Disclosure
CVSS 6.5
CVE-2026-22748
MEDIUM
Potential Security Misconfiguration when Using withIssuerLocation
CVSS 5.3
CVE-2026-40871
HIGH
mailcow: dockerized vulnerable to Second Order SQL Injection in quarantine category via API
CVSS 7.2
CVE-2026-6779
MEDIUM
Mozilla Firefox and Thunderbird 150 - JavaScript Engine Memory Safety Issue
CVSS 5.3
CVE-2026-6777
MEDIUM
Mozilla Firefox and Thunderbird 150 - DNS Component Input Validation Issue
CVSS 5.3
CVE-2026-6675
MEDIUM
Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter
CVSS 5.3
CVE-2026-39386
HIGH
Neko has Self-service Privilege Escalation for Authenticated Users
CVSS 8.8
CVE-2026-32604
CRITICAL
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVSS 9.9
CVE-2026-24505
HIGH
Dell PowerProtect Data Domain 8.5-8.6 - Command Injection
CVSS 7.2
CVE-2026-24504
HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6 - Command Injection
CVSS 7.2
CVE-2026-6626
MEDIUM
Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection
CVSS 6.3
CVE-2026-40317
CRITICAL
NovumOS has Privilege Escalation in the Syscall Interface
CVSS 9.3
CVE-2026-33436
LOW
Stirling-PDF: Reflected XSS through crafted filename in file upload functionality
CVSS 3.1
Details
Vulnerabilities
12,423
Exploit Likelihood
High