CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,039 vulnerabilities with CWE-20
CVE-2026-32604 CRITICAL
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVSS 9.9
CVE-2026-24505 HIGH
Dell PowerProtect Data Domain 8.5-8.6 - Command Injection
CVSS 7.2
CVE-2026-24504 HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6 - Command Injection
CVSS 7.2
CVE-2026-6626 MEDIUM
Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection
CVSS 6.3
CVE-2026-40317 CRITICAL
NovumOS has Privilege Escalation in the Syscall Interface
CVSS 9.3
CVE-2026-33436 LOW
Stirling-PDF: Reflected XSS through crafted filename in file upload functionality
CVSS 3.1
CVE-2026-6409 HIGH
Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input
CVE-2026-22615 MEDIUM
Eaton IPP Software <2.0 - Command Injection
CVSS 6.0
CVE-2026-40261 HIGH
Composer has Command Injection via Malicious Perforce Reference
CVSS 8.8
CVE-2026-40176 HIGH
Composer is vulnerable to Command Injection via Malicious Perforce Repository
CVSS 7.8
CVE-2026-1782 MEDIUM
MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'
CVSS 5.3
CVE-2026-6328 HIGH
XQUIC Improper STREAM Frame Validation in Initial/Handshake Packets
CVE-2026-39399 CRITICAL
NuGet Gallery: Arbitrary Blob Overwrite via Nuspec Confusion and URI Fragment Truncation
CVSS 9.6
CVE-2026-35031 CRITICAL
Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain
CVSS 9.9
CVE-2026-27299 MEDIUM
Adobe Framemaker | Improper Input Validation (CWE-20)
CVSS 6.3
CVE-2026-27306 HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 8.4
CVE-2026-27304 CRITICAL
ColdFusion | Improper Input Validation (CWE-20)
CVSS 9.3
CVE-2026-27282 HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 7.5
CVE-2026-24893 HIGH
openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion
CVSS 8.8
CVE-2026-33826 HIGH
Windows Active Directory Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-33116 HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-32203 HIGH
.NET and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-32201 MEDIUM KEV
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 6.5
CVE-2026-32168 HIGH
Azure Monitor Agent Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-32149 HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.3
Details
Vulnerabilities 12,039
Exploit Likelihood High