CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,842 vulnerabilities with CWE-20
CVE-2026-42389 MEDIUM
PowerDNS Recursor - Reject More Queries with Invalid Header Values
CVSS 5.3
CVE-2026-42388 MEDIUM
PowerDNS Recursor - Missing Input Validation for Catalog Zones
CVSS 5.9
CVE-2026-42387 MEDIUM
PowerDNS Recursor - Insufficient Input Validation in ZoneToCache
CVSS 5.9
CVE-2026-12246 HIGH
NLnet Labs NSD < 4.14.3 - APL RR Stack Buffer Overflow
CVSS 8.1
CVE-2026-52801 HIGH
Gogs: Ability to import local repositories via Mirror Settings
CVSS 8.1
CVE-2026-13025 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-13024 MEDIUM
Google Chrome - Improper Input Validation
CVSS 4.2
CVE-2026-48720 HIGH
Warp: SSH remote output can lead to local file overwrite and persistence
CVSS 8.8
CVE-2026-48704 HIGH
Warp Markdown notebook links may open executable local files
CVSS 8.8
CVE-2026-12537 HIGH
Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows
CVSS 7.8
CVE-2026-13006 HIGH
QOS.CH Sarl Logback-core - Incomplete Protection Against CVE-2025-11226
CVE-2026-54588 CRITICAL
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
CVSS 9.6
CVE-2026-45135 HIGH
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVSS 8.1
CVE-2026-49444 HIGH
n8n: Python sandbox escape
CVSS 8.5
CVE-2026-56762 MEDIUM
Hono - Missing Cookie Name Validation in setCookie()
CVSS 5.3
CVE-2026-10651 HIGH
Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read
CVSS 7.1
CVE-2026-56306 MEDIUM
Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing
CVSS 6.4
CVE-2026-54911 MEDIUM
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
CVSS 6.5
CVE-2026-48109 HIGH
MessagePack-CSharp LZ4 - Out-of-Bounds Read Denial of Service
CVSS 8.2
CVE-2026-54299 HIGH
Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)
CVSS 7.5
CVE-2026-55602 HIGH
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
CVSS 8.6
CVE-2026-53537 LOW
Python-Multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVSS 3.7
CVE-2026-7165 CRITICAL
Gaudire Assassin Game addJugador - Privilege Escalation and Server-Side Request Forgery
CVE-2026-12787 MEDIUM
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserialization
CVSS 6.3
CVE-2026-56340 HIGH
vLLM - Denial of Service via Unvalidated Multimodal Embeddings
CVSS 8.8
Details
Vulnerabilities 12,842
Exploit Likelihood High