CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,423 vulnerabilities with CWE-20
CVE-2026-26156 HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-26154 HIGH
Windows Server Update Service (WSUS) Tampering Vulnerability
CVSS 7.5
CVE-2026-26143 HIGH
Microsoft PowerShell Security Feature Bypass Vulnerability
CVSS 7.8
CVE-2026-39417 MEDIUM
MaxKB: RCE via MCP stdio command injection in workflow engine
CVSS 4.6
CVE-2026-33948 MEDIUM
jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
CVSS 5.3
CVE-2026-22565 HIGH
UniFi Play PowerAmp < 1.0.38 and UniFi Play Audio Port < 1.1.9 - Denial of Service
CVSS 7.5
CVE-2026-22563 CRITICAL
UniFi Play PowerAmp < 1.0.38 and UniFi Play Audio Port < 1.1.9 - Command Injection via Improper Input Validation
CVSS 9.8
CVE-2026-6231 MEDIUM
bson_validate may skip validation when processing certain inputs
CVSS 4.3
CVE-2026-34855 MEDIUM
Huawei HarmonyOS and EMUI - Out-of-bounds Write in Kernel Module
CVSS 5.7
CVE-2026-40162 HIGH
Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble
CVSS 7.1
CVE-2026-5500 MEDIUM
Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass
CVSS 5.9
CVE-2026-33797 HIGH
Junos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP reset
CVSS 7.4
CVE-2026-32990 MEDIUM
Apache Tomcat: Fix for CVE-2025-66614 is incomplete
CVSS 5.3
CVE-2026-5329 HIGH
Rapid7 Velociraptor Improper Input Validation in Client Message Handler
CVSS 8.5
CVE-2026-34178 CRITICAL
Importing a crafted backup leads to project restriction bypass
CVSS 9.1
CVE-2026-5919 MEDIUM
Google Chrome <147.0.7727.55 - Auth Bypass
CVSS 6.5
CVE-2026-5915 HIGH
Google Chrome < 147.0.7727.55 - Out of Bounds Memory Write in WebML
CVSS 8.1
CVE-2026-5887 MEDIUM
Google Chrome <147.0.7727.55 - Auth Bypass
CVSS 4.3
CVE-2026-5885 MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 6.5
CVE-2026-5884 HIGH
Google Chrome <147.0.7727.55 - Code Injection
CVSS 8.8
CVE-2026-5879 HIGH
Google Chrome <147.0.7727.55 - Code Injection
CVSS 8.8
CVE-2026-39410 MEDIUM
Hono <4.12.12 getCookie() - Cookie Prefix Bypass
CVSS 4.8
CVE-2026-34197 HIGH KEV
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
CVE-2026-5659 MEDIUM
pytries datrie trie File datrie.pyx Trie.__setstate__ deserialization
CVSS 6.3
CVE-2026-30078 HIGH
OpenAirInterface oai-cn5g-amf - Denial of Service via Invalid NGAP Message Procedure Code or PDU-Type
CVSS 7.5
Details
Vulnerabilities 12,423
Exploit Likelihood High