CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,842 vulnerabilities with CWE-20
CVE-2026-0416 MEDIUM
RAXE450 and RAXE500 routers allow administrators to modify router functionality beyond intended limits
CVSS 4.5
CVE-2026-0415 MEDIUM
NETGEAR Orbi Routers - Authenticated Unauthorized Software Modification
CVSS 4.5
CVE-2026-0412 MEDIUM
NETGEAR JR6150 Web UI - Authenticated Unauthorized Software Modification
CVSS 4.5
CVE-2026-0410 MEDIUM
Insufficient input validation in certain NETGEAR routers
CVSS 4.5
CVE-2026-11701 MEDIUM
Google Chrome - Improper Input Validation
CVSS 5.4
CVE-2026-11697 CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
CVE-2026-11691 LOW
Google Chrome - Improper Input Validation
CVSS 3.1
CVE-2026-11689 HIGH
Google Chrome - Improper Input Validation
CVSS 8.1
CVE-2026-11686 LOW
Google Chrome - Improper Input Validation
CVSS 3.1
CVE-2026-11685 MEDIUM
Google Chrome < 149.0.7827.103 - Cross-Origin Data Leak via MediaCapture
CVSS 4.3
CVE-2026-11682 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-11676 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-11675 LOW
Google Chrome - Improper Input Validation
CVSS 3.1
CVE-2026-11666 MEDIUM
Google Chrome - Improper Input Validation
CVSS 5.4
CVE-2026-11660 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-11659 CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
CVE-2026-11658 MEDIUM
Google Chrome - Improper Input Validation
CVSS 6.5
CVE-2026-11653 MEDIUM
Google Chrome - Improper Input Validation
CVSS 6.5
CVE-2026-49234 HIGH
Routinator crashes on specifically crafted ASN strings in the API
CVSS 7.5
CVE-2026-47430 HIGH
Apache Cordova InAppBrowser iOS 3.1.0-6.0.0 - Callback ID Spoofing
CVSS 7.5
CVE-2026-11460 HIGH
Boost Serialization improper validation of specified type of input
CVSS 7.3
CVE-2026-46357 MEDIUM
HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Request
CVSS 6.5
CVE-2026-45291 HIGH
Cloudburst Network erroneously handles invalid connections
CVSS 7.5
CVE-2026-36501 HIGH
Controller 12.0.5 - Denial of Service via Externalizable.readExternal()
CVSS 7.5
CVE-2026-8714 MEDIUM
Denial-of-Service Vulnerability in RTSP Input Handling on TP-Link's Tapo C520WS
CVSS 6.5
Details
Vulnerabilities 12,842
Exploit Likelihood High