CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,433 vulnerabilities with CWE-20
CVE-2026-25117 HIGH
pwn.college DOJO <e33da14449a5abcff507e554f66e2141d6683b0a - XSS
CVE-2026-23571 MEDIUM
TeamViewer DEX < 26.1 - Authenticated Command Injection via 1E-Nomad-RunPkgStatusRequest Input Field
CVSS 6.8
CVE-2026-23570 MEDIUM
TeamViewer DEX Client <26.1 - Info Disclosure
CVSS 6.5
CVE-2026-23566 MEDIUM
TeamViewer DEX Client <26.1 - Log Injection
CVSS 6.5
CVE-2026-24856 HIGH
iccDEV < 2.3.1.2 - Memory Corruption via Floating-Point NaN to Unsigned Short Conversion
CVSS 7.8
CVE-2026-1315 HIGH
TP-Link Tapo C220 and C520WS Firmware - Unauthenticated Denial of Service via Firmware Update Endpoint
CVSS 7.5
CVE-2026-0919 HIGH
TP-Link Tapo C210 v3 C220 v1 C520WS v2 - Unauthenticated Denial of Service via Long URL Path
CVSS 7.5
CVE-2026-24348 MEDIUM
EZCast Pro II Firmware 1.17478.146 - Cross-Site Scripting in Admin UI
CVSS 6.1
CVE-2026-24347 MEDIUM
EZCast Pro II <1.17478.146 - Path Traversal
CVSS 5.3
CVE-2026-24345 HIGH
EZCast Pro II Firmware 1.17478.146 - Cross-Site Request Forgery in Admin UI
CVSS 8.8
CVE-2026-24811 CRITICAL
root < 6.34.08 - Out-of-bounds Read in builtins/zlib inffast.C
CVSS 9.8
CVE-2026-24412 HIGH
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagXmlSegmentedCurve::ToXml()
CVSS 8.8
CVE-2026-24411 HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-24410 HIGH
iccDEV < 2.3.1.2 - Null Pointer Dereference in CIccProfileXml::ParseBasic()
CVSS 7.1
CVE-2026-24409 HIGH
iccdev < 2.3.1.2 - Null Pointer Dereference in CIccTagXmlFloatNum ParseXml
CVSS 7.1
CVE-2026-24407 HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-24406 HIGH
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagNamedColor2::SetSize()
CVSS 8.8
CVE-2026-24405 HIGH
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in CIccMpeCalculator::Read()
CVSS 8.8
CVE-2026-24404 HIGH
iccDEV <2.3.1.1 - Null Pointer Dereference
CVSS 7.1
CVE-2026-24403 HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-1225 LOW
logback-core <= 1.5.24 - Arbitrary Class Instantiation via Configuration File Processing
CVE-2026-23887 MEDIUM
Group-Office <6.8.148 & 25.0.1-25.0.79 - XSS
CVSS 5.4
CVE-2026-22598 HIGH
ManageIQ < radjabov-2 - Denial of Service via Malformed TimeProfile
CVE-2026-22444 HIGH
Apache Solr 8.6.0-9.10.0 - Unauthenticated Path Traversal via Create Core API
CVSS 7.1
CVE-2026-0933 CRITICAL
Cloudflare Wrangler 2.0.15-3.114.17 - OS Command Injection via --commit-hash Parameter
CVSS 9.9
Details
Vulnerabilities 12,433
Exploit Likelihood High