CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,842 vulnerabilities with CWE-20
CVE-2026-45329 HIGH
Espressif ESP-IDF ESP-TEE Secure Services - TEE Memory Disclosure
CVSS 7.1
CVE-2026-45328 CRITICAL
Espressif ESP-IDF ESP-TEE Secure Services - Out-of-Bounds Write
CVSS 9.3
CVE-2026-41727 MEDIUM
In Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behavior
CVSS 6.5
CVE-2026-47903 MEDIUM
CAI Content Credentials | Improper Input Validation (CWE-20)
CVSS 6.2
CVE-2026-34712 HIGH
CAI Content Credentials | Improper Input Validation (CWE-20)
CVSS 7.5
CVE-2026-47931 HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 8.4
CVE-2026-47930 HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 8.1
CVE-2026-47928 CRITICAL
ColdFusion | Improper Input Validation (CWE-20)
CVSS 9.6
CVE-2026-47909 MEDIUM
Dreamweaver Desktop | Improper Input Validation (CWE-20)
CVSS 6.3
CVE-2026-9213 HIGH
Insufficient input validation in certain NETGEAR routers
CVSS 8.1
CVE-2026-9212 HIGH
Insufficient authentication and input validation in certain NETGEAR products
CVSS 8.0
CVE-2026-9211 HIGH
Certain NETGEAR routers allow unauthenticated users to gain control of the router
CVSS 8.8
CVE-2026-9210 MEDIUM
Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router
CVSS 4.5
CVE-2026-49840 CRITICAL
FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
CVSS 9.1
CVE-2026-49475 HIGH
FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing
CVSS 7.5
CVE-2026-48569 HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 7.1
CVE-2026-48289 LOW
Adobe Experience Manager | Improper Input Validation (CWE-20)
CVSS 3.5
CVE-2026-48288 LOW
Adobe Experience Manager | Improper Input Validation (CWE-20)
CVSS 3.5
CVE-2026-47641 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-45642 LOW
Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability
CVSS 3.9
CVE-2026-45636 HIGH
Microsoft Windows 10 Version 1607 - Windows NTFS Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-44811 HIGH
Microsoft Windows 11 version 26H1 - Windows DWM Core Library Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40376 HIGH
Visual Studio Code Elevation of Privilege Vulnerability
CVSS 7.5
CVE-2026-0419 HIGH
NETGEAR JR6150 - Local WiFi OS Command Injection
CVSS 8.0
CVE-2026-0417 MEDIUM
Insufficient input validation in certain NETGEAR routers
CVSS 4.5
Details
Vulnerabilities 12,842
Exploit Likelihood High