The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,427 vulnerabilities with CWE-20
CVE-2026-2555
MEDIUM
JeecgBoot 3.9.1 - Deserialization via AiragKnowledgeController importDocumentFromZip
CVSS 5.0
CVE-2026-2391
LOW
qs 6.7.0-6.14.2 - Comma Array Limit Denial of Service
CVSS 3.7
CVE-2026-20627
MEDIUM
iPadOS < 26.3 - Unprotected User Data Exposure via Environment Variable Handling
CVSS 5.5
CVE-2026-21258
MEDIUM
Microsoft Office Excel - Info Disclosure
CVSS 5.5
CVE-2026-21247
HIGH
Windows 10 1809 < 10.0.17763.8389 - Authenticated Heap-based Buffer Overflow
CVSS 7.3
CVE-2026-21229
HIGH
Power BI Report Server < 15.0.1120.113 - Authenticated Remote Code Execution
CVSS 8.0
CVE-2026-25892
HIGH
Adminer < 5.4.2 - Denial of Service via Unvalidated Version Check POST
CVSS 7.5
CVE-2026-2113
HIGH
yuan1994 tpadmin <1.3.12 - Deserialization
CVSS 7.3
CVE-2026-25631
MEDIUM
NPM N8n < 1.121.0 - Improper Input Validation
CVSS 6.5
CVE-2026-25723
MEDIUM
Claude Code < 2.0.55 - Authenticated Arbitrary File Write via Piped Sed Command Bypass
CVSS 6.5
CVE-2026-25722
CRITICAL
Claude Code < 2.0.57 - Unauthenticated Path Traversal and Arbitrary File Write via Directory Change Command
CVSS 9.1
CVE-2026-25514
HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via Autocomplete CodeModel::all() Method
CVSS 8.8
CVE-2026-25513
HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
CVE-2026-21893
HIGH
NPM N8n < 1.120.3 - OS Command Injection
CVSS 7.2
CVE-2026-24512
HIGH
Kubernetes ingress-nginx Path Field - Controller Code Execution
CVSS 8.8
CVE-2026-1580
HIGH
ingress-nginx < 1.13.7 and < 1.14.3 - Remote Code Execution via Auth-Method Annotation Injection
CVSS 8.8
CVE-2026-22220
MEDIUM
TP-Link Archer BE230 < 1.2.4 - Denial of Service via HTTP Request
CVSS 4.5
CVE-2026-24936
CRITICAL
ASUSTOR ADM AD Domain CGI - Arbitrary File Write System Compromise
CVSS 9.8
CVE-2026-1691
MEDIUM
bolo-solo < 2.6.4 - Remote Code Execution via SnakeYAML Deserialization
CVSS 6.3
CVE-2026-25128
HIGH
fast-xml-parser 5.0.9-5.3.3 - Denial of Service via Out-of-Range XML Entity Code Points
CVSS 7.5
CVE-2026-25126
HIGH
PolarLearn <0-PRERELEASE-15 - Info Disclosure
CVSS 7.1
CVE-2026-25117
HIGH
pwn.college DOJO <e33da14449a5abcff507e554f66e2141d6683b0a - XSS
CVE-2026-23571
MEDIUM
TeamViewer DEX < 26.1 - Authenticated Command Injection via 1E-Nomad-RunPkgStatusRequest Input Field
CVSS 6.8
CVE-2026-23570
MEDIUM
TeamViewer DEX Client <26.1 - Info Disclosure
CVSS 6.5
CVE-2026-23566
MEDIUM
TeamViewer DEX Client <26.1 - Log Injection
CVSS 6.5
Details
Vulnerabilities
12,427
Exploit Likelihood
High