The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,039 vulnerabilities with CWE-20
CVE-2026-32604
CRITICAL
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVSS 9.9
CVE-2026-24505
HIGH
Dell PowerProtect Data Domain 8.5-8.6 - Command Injection
CVSS 7.2
CVE-2026-24504
HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6 - Command Injection
CVSS 7.2
CVE-2026-6626
MEDIUM
Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection
CVSS 6.3
CVE-2026-40317
CRITICAL
NovumOS has Privilege Escalation in the Syscall Interface
CVSS 9.3
CVE-2026-33436
LOW
Stirling-PDF: Reflected XSS through crafted filename in file upload functionality
CVSS 3.1
CVE-2026-6409
HIGH
Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input
CVE-2026-22615
MEDIUM
Eaton IPP Software <2.0 - Command Injection
CVSS 6.0
CVE-2026-40261
HIGH
Composer has Command Injection via Malicious Perforce Reference
CVSS 8.8
CVE-2026-40176
HIGH
Composer is vulnerable to Command Injection via Malicious Perforce Repository
CVSS 7.8
CVE-2026-1782
MEDIUM
MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'
CVSS 5.3
CVE-2026-6328
HIGH
XQUIC Improper STREAM Frame Validation in Initial/Handshake Packets
CVE-2026-39399
CRITICAL
NuGet Gallery: Arbitrary Blob Overwrite via Nuspec Confusion and URI Fragment Truncation
CVSS 9.6
CVE-2026-35031
CRITICAL
Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain
CVSS 9.9
CVE-2026-27299
MEDIUM
Adobe Framemaker | Improper Input Validation (CWE-20)
CVSS 6.3
CVE-2026-27306
HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 8.4
CVE-2026-27304
CRITICAL
ColdFusion | Improper Input Validation (CWE-20)
CVSS 9.3
CVE-2026-27282
HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 7.5
CVE-2026-24893
HIGH
openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion
CVSS 8.8
CVE-2026-33826
HIGH
Windows Active Directory Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-33116
HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-32203
HIGH
.NET and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-32201
MEDIUM
KEV
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 6.5
CVE-2026-32168
HIGH
Azure Monitor Agent Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-32149
HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.3
Details
Vulnerabilities
12,039
Exploit Likelihood
High