The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,842 vulnerabilities with CWE-20
CVE-2026-56325
LOW
Capgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup
CVSS 3.1
CVE-2026-56228
MEDIUM
Capgo - Denial of Service via Improper Password Policy Length Validation
CVSS 4.9
CVE-2026-48774
HIGH
ProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contract
CVSS 7.5
CVE-2026-21768
MEDIUM
HCL Verse for Android is susceptible to an injection vulnerability
CVSS 6.3
CVE-2026-39998
HIGH
Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
CVSS 8.8
CVE-2026-12569
CRITICAL
KEV
PTC Windchill PDMLink and FlexPLM - Deserialization Remote Code Execution
CVSS 9.8
CVE-2026-50196
HIGH
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVSS 7.5
CVE-2026-48055
CRITICAL
Streambert: Arbitrary File Write (Zip Slip) via Subtitle Extraction
CVSS 10.0
CVE-2026-12465
HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-12456
MEDIUM
Google Chrome - Improper Input Validation
CVSS 4.2
CVE-2026-12453
MEDIUM
Google Chrome - Improper Input Validation
CVSS 4.2
CVE-2026-46910
CRITICAL
Oracle Corporation JD Edwards EnterpriseOne Tools < 9.2.26.2 - Denial of Service
CVSS 9.1
CVE-2026-0142
LOW
Google Android - Information Disclosure
CVSS 3.3
CVE-2026-12191
HIGH
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
CVSS 7.8
CVE-2026-45013
HIGH
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
CVSS 8.1
CVE-2026-54133
CRITICAL
jmespath.php has CompilerRuntime code injection via unescaped function names
CVSS 9.8
CVE-2026-47196
HIGH
Quest Bot: Empty automod rule causes every guild message to be deleted
CVE-2026-50633
HIGH
Apache CXF JCA Integration - JNDI Injection Remote Code Execution
CVSS 8.1
CVE-2026-50632
HIGH
Apache CXF JMSConfigFactory - JNDI Injection Remote Code Execution
CVSS 8.1
CVE-2026-50628
CRITICAL
Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
CVSS 9.8
CVE-2026-47370
CRITICAL
Ubiquiti INC UniFi OS Server - Improper Input Validation
CVSS 9.9
CVE-2026-47369
CRITICAL
Ubiquiti INC UniFi OS Server - Improper Input Validation
CVSS 9.9
CVE-2026-47367
CRITICAL
Ubiquiti INC Uid Enterprise Agent < 1.61.4 - Improper Input Validation
CVSS 9.9
CVE-2026-12034
HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-12025
MEDIUM
Google Chrome - Improper Input Validation
CVSS 5.3
Details
Vulnerabilities
12,842
Exploit Likelihood
High