CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,424 vulnerabilities with CWE-20
CVE-2026-33029 MEDIUM
Nginx UI: DoS via Negative Integer Input in Logrotate Interval
CVSS 6.5
CVE-2026-30077 HIGH
OpenAirInterface V2.2.0 - Denial of Service via Malformed Message Decoding
CVSS 7.5
CVE-2026-29909 MEDIUM
MRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module
CVSS 5.3
CVE-2026-21712 MEDIUM
Node.js 24.14.0 and 25.8.1 - Denial of Service via Malformed IDN in url.format()
CVSS 5.7
CVE-2026-4987 HIGH
SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'
CVSS 7.5
CVE-2026-33936 MEDIUM
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVSS 5.3
CVE-2026-33894 HIGH
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
CVSS 7.5
CVE-2026-33882 MEDIUM
Statamic's Markdown preview endpoint exposes sensitive user data
CVSS 6.5
CVE-2026-30576 HIGH
SourceCodester Pharmacy Product Management System 1.0 - Business Logic
CVSS 7.5
CVE-2026-30575 HIGH
SourceCodester Pharmacy Product Management System 1.0 - DoS
CVSS 7.5
CVE-2026-33758 MEDIUM
OpenBao has Reflected XSS in its OIDC authentication error message
CVSS 6.1
CVE-2026-33284 MEDIUM
GlobalLeaks has insufficient URL validation in user support API
CVSS 4.3
CVE-2026-30304 CRITICAL
AI Code < 3.12.4 - Remote Code Execution via Prompt Injection
CVSS 9.6
CVE-2026-4982 HIGH
Unauthorized access to chat contents
CVE-2026-33729 CRITICAL
OpenFGA <1.13.1 Condition Cache Keys - Authorization Bypass
CVSS 9.8
CVE-2026-29905 MEDIUM
Kirby CMS < 5.1.4 - Authenticated Denial of Service via Malformed Image Upload
CVSS 6.5
CVE-2026-4860 HIGH
648540858 wvp-GB28181-pro API Endpoint RedisTemplateConfig.java GenericFastJsonRedisSerializer deserialization
CVSS 7.3
CVE-2026-33287 HIGH
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
CVSS 7.5
CVE-2026-33285 HIGH
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
CVSS 7.5
CVE-2026-33218 HIGH
NATS has pre-auth server panic via leafnode handling
CVSS 7.5
CVE-2026-28894 HIGH
iOS and iPadOS < 26.4 - Denial of Service via Improved Input Validation
CVSS 7.5
CVE-2026-28852 MEDIUM
iOS and iPadOS < 18.7.7 - Denial of Service via Stack Overflow
CVSS 5.5
CVE-2026-28821 HIGH
macOS <14.8.5 - Privilege Escalation
CVSS 8.4
CVE-2026-20686 MEDIUM
iOS and iPadOS < 26.3 - Unprotected User Data Exposure via Input Validation Issue
CVSS 5.3
CVE-2026-3912 HIGH
TIBCO ActiveMatrix BusinessWorks Injection Vulnerability
Details
Vulnerabilities 12,424
Exploit Likelihood High