CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,423 vulnerabilities with CWE-20
CVE-2026-46679 HIGH
libp2p: Memory DoS via subscription flood of unique topics
CVSS 7.5
CVE-2026-46669 HIGH
`openvm-pairing` pairing check missing proper subfield check on scaling factor
CVSS 7.5
CVE-2026-45783 HIGH
libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
CVSS 7.5
CVE-2026-50569 MEDIUM
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
CVSS 4.3
CVE-2026-45062 HIGH
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
CVSS 8.1
CVE-2026-20257 MEDIUM
Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise
CVSS 5.7
CVE-2026-20256 MEDIUM
Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise
CVSS 5.7
CVE-2026-20255 MEDIUM
Improper Input Validation through Classic Dashboards in Splunk Enterprise
CVSS 5.7
CVE-2026-20254 MEDIUM
Information Disclosure through External Content Restriction Bypass in Splunk Enterprise
CVSS 5.7
CVE-2026-45565 HIGH
Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)
CVSS 8.1
CVE-2026-45558 CRITICAL
Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section save
CVSS 9.9
CVE-2026-45556 CRITICAL
Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`
CVSS 9.9
CVE-2026-45329 HIGH
Espressif ESP-IDF ESP-TEE Secure Services - TEE Memory Disclosure
CVSS 7.1
CVE-2026-45328 CRITICAL
Espressif ESP-IDF ESP-TEE Secure Services - Out-of-Bounds Write
CVSS 9.3
CVE-2026-41727 MEDIUM
In Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behavior
CVSS 6.5
CVE-2026-47903 MEDIUM
CAI Content Credentials | Improper Input Validation (CWE-20)
CVSS 6.2
CVE-2026-34712 HIGH
CAI Content Credentials | Improper Input Validation (CWE-20)
CVSS 7.5
CVE-2026-47931 HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 8.4
CVE-2026-47930 HIGH
ColdFusion | Improper Input Validation (CWE-20)
CVSS 8.1
CVE-2026-47928 CRITICAL
ColdFusion | Improper Input Validation (CWE-20)
CVSS 9.6
CVE-2026-47909 MEDIUM
Dreamweaver Desktop | Improper Input Validation (CWE-20)
CVSS 6.3
CVE-2026-9213 MEDIUM
Insufficient input validation in certain NETGEAR routers
CVE-2026-9212 MEDIUM
Insufficient authentication and input validation in certain NETGEAR products
CVE-2026-9211 MEDIUM
Certain NETGEAR routers allow unauthenticated users to gain control of the router
CVE-2026-9210 MEDIUM
Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router
Details
Vulnerabilities 12,423
Exploit Likelihood High