CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,842 vulnerabilities with CWE-20
CVE-2026-12017 LOW
Google Chrome - Improper Input Validation
CVSS 3.1
CVE-2026-12016 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-12009 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-47181 HIGH
PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account Takeover
CVE-2026-49982 HIGH
node-tmp 0.2.6 - Path Traversal via Non-String Template Values
CVSS 8.2
CVE-2026-53723 MEDIUM
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
CVSS 5.8
CVE-2026-49214 MEDIUM
guzzlehttp/psr7 has CRLF Injection via URI Host Component
CVSS 5.3
CVE-2026-48998 MEDIUM
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVSS 5.3
CVE-2026-53901 HIGH
Cerebrate before v1.37 allows mass assignment of record identifiers during object creation
CVE-2026-49218 HIGH
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
CVSS 7.5
CVE-2026-48110 HIGH
Russh: SSH message fields were decoded through allocation-first parsers before field-specific bounds
CVSS 7.5
CVE-2026-48108 MEDIUM
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
CVSS 5.3
CVE-2026-48107 MEDIUM
Russh: Unchecked keyboard-interactive prompt count in client auth path
CVSS 6.5
CVE-2026-46679 HIGH
libp2p: Memory DoS via subscription flood of unique topics
CVSS 7.5
CVE-2026-46669 HIGH
`openvm-pairing` pairing check missing proper subfield check on scaling factor
CVSS 7.5
CVE-2026-45783 HIGH
libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
CVSS 7.5
CVE-2026-50569 MEDIUM
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
CVSS 4.3
CVE-2026-45062 HIGH
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
CVSS 8.1
CVE-2026-20257 MEDIUM
Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise
CVSS 5.7
CVE-2026-20256 MEDIUM
Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise
CVSS 5.7
CVE-2026-20255 MEDIUM
Improper Input Validation through Classic Dashboards in Splunk Enterprise
CVSS 5.7
CVE-2026-20254 MEDIUM
Information Disclosure through External Content Restriction Bypass in Splunk Enterprise
CVSS 5.7
CVE-2026-45565 HIGH
Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)
CVSS 8.1
CVE-2026-45558 CRITICAL
Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section save
CVSS 9.9
CVE-2026-45556 CRITICAL
Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`
CVSS 9.9
Details
Vulnerabilities 12,842
Exploit Likelihood High