CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,427 vulnerabilities with CWE-20
CVE-2026-2555 MEDIUM
JeecgBoot 3.9.1 - Deserialization via AiragKnowledgeController importDocumentFromZip
CVSS 5.0
CVE-2026-2391 LOW
qs 6.7.0-6.14.2 - Comma Array Limit Denial of Service
CVSS 3.7
CVE-2026-20627 MEDIUM
iPadOS < 26.3 - Unprotected User Data Exposure via Environment Variable Handling
CVSS 5.5
CVE-2026-21258 MEDIUM
Microsoft Office Excel - Info Disclosure
CVSS 5.5
CVE-2026-21247 HIGH
Windows 10 1809 < 10.0.17763.8389 - Authenticated Heap-based Buffer Overflow
CVSS 7.3
CVE-2026-21229 HIGH
Power BI Report Server < 15.0.1120.113 - Authenticated Remote Code Execution
CVSS 8.0
CVE-2026-25892 HIGH
Adminer < 5.4.2 - Denial of Service via Unvalidated Version Check POST
CVSS 7.5
CVE-2026-2113 HIGH
yuan1994 tpadmin <1.3.12 - Deserialization
CVSS 7.3
CVE-2026-25631 MEDIUM
NPM N8n < 1.121.0 - Improper Input Validation
CVSS 6.5
CVE-2026-25723 MEDIUM
Claude Code < 2.0.55 - Authenticated Arbitrary File Write via Piped Sed Command Bypass
CVSS 6.5
CVE-2026-25722 CRITICAL
Claude Code < 2.0.57 - Unauthenticated Path Traversal and Arbitrary File Write via Directory Change Command
CVSS 9.1
CVE-2026-25514 HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via Autocomplete CodeModel::all() Method
CVSS 8.8
CVE-2026-25513 HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
CVE-2026-21893 HIGH
NPM N8n < 1.120.3 - OS Command Injection
CVSS 7.2
CVE-2026-24512 HIGH
Kubernetes ingress-nginx Path Field - Controller Code Execution
CVSS 8.8
CVE-2026-1580 HIGH
ingress-nginx < 1.13.7 and < 1.14.3 - Remote Code Execution via Auth-Method Annotation Injection
CVSS 8.8
CVE-2026-22220 MEDIUM
TP-Link Archer BE230 < 1.2.4 - Denial of Service via HTTP Request
CVSS 4.5
CVE-2026-24936 CRITICAL
ASUSTOR ADM AD Domain CGI - Arbitrary File Write System Compromise
CVSS 9.8
CVE-2026-1691 MEDIUM
bolo-solo < 2.6.4 - Remote Code Execution via SnakeYAML Deserialization
CVSS 6.3
CVE-2026-25128 HIGH
fast-xml-parser 5.0.9-5.3.3 - Denial of Service via Out-of-Range XML Entity Code Points
CVSS 7.5
CVE-2026-25126 HIGH
PolarLearn <0-PRERELEASE-15 - Info Disclosure
CVSS 7.1
CVE-2026-25117 HIGH
pwn.college DOJO <e33da14449a5abcff507e554f66e2141d6683b0a - XSS
CVE-2026-23571 MEDIUM
TeamViewer DEX < 26.1 - Authenticated Command Injection via 1E-Nomad-RunPkgStatusRequest Input Field
CVSS 6.8
CVE-2026-23570 MEDIUM
TeamViewer DEX Client <26.1 - Info Disclosure
CVSS 6.5
CVE-2026-23566 MEDIUM
TeamViewer DEX Client <26.1 - Log Injection
CVSS 6.5
Details
Vulnerabilities 12,427
Exploit Likelihood High