The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,433 vulnerabilities with CWE-20
CVE-2026-25117
HIGH
pwn.college DOJO <e33da14449a5abcff507e554f66e2141d6683b0a - XSS
CVE-2026-23571
MEDIUM
TeamViewer DEX < 26.1 - Authenticated Command Injection via 1E-Nomad-RunPkgStatusRequest Input Field
CVSS 6.8
CVE-2026-23570
MEDIUM
TeamViewer DEX Client <26.1 - Info Disclosure
CVSS 6.5
CVE-2026-23566
MEDIUM
TeamViewer DEX Client <26.1 - Log Injection
CVSS 6.5
CVE-2026-24856
HIGH
iccDEV < 2.3.1.2 - Memory Corruption via Floating-Point NaN to Unsigned Short Conversion
CVSS 7.8
CVE-2026-1315
HIGH
TP-Link Tapo C220 and C520WS Firmware - Unauthenticated Denial of Service via Firmware Update Endpoint
CVSS 7.5
CVE-2026-0919
HIGH
TP-Link Tapo C210 v3 C220 v1 C520WS v2 - Unauthenticated Denial of Service via Long URL Path
CVSS 7.5
CVE-2026-24348
MEDIUM
EZCast Pro II Firmware 1.17478.146 - Cross-Site Scripting in Admin UI
CVSS 6.1
CVE-2026-24347
MEDIUM
EZCast Pro II <1.17478.146 - Path Traversal
CVSS 5.3
CVE-2026-24345
HIGH
EZCast Pro II Firmware 1.17478.146 - Cross-Site Request Forgery in Admin UI
CVSS 8.8
CVE-2026-24811
CRITICAL
root < 6.34.08 - Out-of-bounds Read in builtins/zlib inffast.C
CVSS 9.8
CVE-2026-24412
HIGH
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagXmlSegmentedCurve::ToXml()
CVSS 8.8
CVE-2026-24411
HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-24410
HIGH
iccDEV < 2.3.1.2 - Null Pointer Dereference in CIccProfileXml::ParseBasic()
CVSS 7.1
CVE-2026-24409
HIGH
iccdev < 2.3.1.2 - Null Pointer Dereference in CIccTagXmlFloatNum ParseXml
CVSS 7.1
CVE-2026-24407
HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-24406
HIGH
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagNamedColor2::SetSize()
CVSS 8.8
CVE-2026-24405
HIGH
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in CIccMpeCalculator::Read()
CVSS 8.8
CVE-2026-24404
HIGH
iccDEV <2.3.1.1 - Null Pointer Dereference
CVSS 7.1
CVE-2026-24403
HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-1225
LOW
logback-core <= 1.5.24 - Arbitrary Class Instantiation via Configuration File Processing
CVE-2026-23887
MEDIUM
Group-Office <6.8.148 & 25.0.1-25.0.79 - XSS
CVSS 5.4
CVE-2026-22598
HIGH
ManageIQ < radjabov-2 - Denial of Service via Malformed TimeProfile
CVE-2026-22444
HIGH
Apache Solr 8.6.0-9.10.0 - Unauthenticated Path Traversal via Create Core API
CVSS 7.1
CVE-2026-0933
CRITICAL
Cloudflare Wrangler 2.0.15-3.114.17 - OS Command Injection via --commit-hash Parameter
CVSS 9.9
Details
Vulnerabilities
12,433
Exploit Likelihood
High