CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,423 vulnerabilities with CWE-20
CVE-2026-7317 MEDIUM
Grav CMS Cache Value FileCache.php doGet deserialization
CVSS 5.0
CVE-2026-24204 MEDIUM
NVIDIA FLARE SDK < 2.7.2 - Path Traversal and Information Disclosure
CVSS 6.5
CVE-2026-5941 HIGH
Foxit PDF Editor/Reader AcroForm Signature Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-41044 HIGH
Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
CVSS 8.8
CVE-2026-40466 HIGH
Apache ActiveMQ Broker < 5.19.6 and 6.0.0 to before 6.2.5 - Remote Code Execution
CVSS 8.8
CVE-2026-41268 HIGH
Flowise: Flowise Parameter Override Bypass Remote Command Execution
CVSS 7.7
CVE-2026-34066 MEDIUM
nimiq-blockchain: Peer-triggerable panic during history sync
CVSS 5.3
CVE-2026-33471 CRITICAL
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
CVSS 9.6
CVE-2026-35380 MEDIUM
uutils coreutils cut Local Logic Error and Data Integrity Issue in Delimiter Parsing
CVSS 5.5
CVE-2026-35377 LOW
uutils coreutils env Local Denial of Service via Improper Handling of Backslashes in Split-String Mode
CVSS 3.3
CVE-2026-35369 MEDIUM
uutils coreutils kill System-wide Process Termination and Denial of Service via Argument Misinterpretation
CVSS 5.5
CVE-2026-35347 MEDIUM
uutils coreutils comm Silent Data Loss or Denial of Service via Improper Input Validation
CVSS 4.4
CVE-2026-31192 MEDIUM
Raindrop.io Bookmark Manager Web App 5.6.76.0 - Info Disclosure
CVSS 6.5
CVE-2026-22748 MEDIUM
Potential Security Misconfiguration when Using withIssuerLocation
CVSS 5.3
CVE-2026-40871 HIGH
mailcow: dockerized vulnerable to Second Order SQL Injection in quarantine category via API
CVSS 7.2
CVE-2026-6779 MEDIUM
Mozilla Firefox and Thunderbird 150 - JavaScript Engine Memory Safety Issue
CVSS 5.3
CVE-2026-6777 MEDIUM
Mozilla Firefox and Thunderbird 150 - DNS Component Input Validation Issue
CVSS 5.3
CVE-2026-6675 MEDIUM
Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter
CVSS 5.3
CVE-2026-39386 HIGH
Neko has Self-service Privilege Escalation for Authenticated Users
CVSS 8.8
CVE-2026-32604 CRITICAL
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVSS 9.9
CVE-2026-24505 HIGH
Dell PowerProtect Data Domain 8.5-8.6 - Command Injection
CVSS 7.2
CVE-2026-24504 HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6 - Command Injection
CVSS 7.2
CVE-2026-6626 MEDIUM
Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection
CVSS 6.3
CVE-2026-40317 CRITICAL
NovumOS has Privilege Escalation in the Syscall Interface
CVSS 9.3
CVE-2026-33436 LOW
Stirling-PDF: Reflected XSS through crafted filename in file upload functionality
CVSS 3.1
Details
Vulnerabilities 12,423
Exploit Likelihood High