CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,039 vulnerabilities with CWE-20
CVE-2026-27928 HIGH
Windows Hello Security Feature Bypass Vulnerability
CVSS 8.7
CVE-2026-27913 HIGH
Windows BitLocker Security Feature Bypass Vulnerability
CVSS 7.7
CVE-2026-27906 MEDIUM
Windows Hello Security Feature Bypass Vulnerability
CVSS 4.4
CVE-2026-26170 HIGH
PowerShell Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-26161 HIGH
Windows Sensor Data Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-26156 HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-26154 HIGH
Windows Server Update Service (WSUS) Tampering Vulnerability
CVSS 7.5
CVE-2026-26143 HIGH
Microsoft PowerShell Security Feature Bypass Vulnerability
CVSS 7.8
CVE-2026-39417 MEDIUM
MaxKB: RCE via MCP stdio command injection in workflow engine
CVSS 4.6
CVE-2026-33948 MEDIUM
jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
CVSS 5.3
CVE-2026-22565 HIGH
UniFi Play PowerAmp <1.0.38 - DoS
CVSS 7.5
CVE-2026-22563 CRITICAL
Ubiquiti INC UniFi Play PowerAmp < 1.0.38 - Command Injection
CVSS 9.8
CVE-2026-6231 MEDIUM
bson_validate may skip validation when processing certain inputs
CVSS 4.3
CVE-2026-34855 MEDIUM
Huawei HarmonyOS < 6.0.0 - Out-of-Bounds Access
CVSS 5.7
CVE-2026-40162 HIGH
Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble
CVSS 7.1
CVE-2026-5500 MEDIUM
Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass
CVSS 5.9
CVE-2026-33797 HIGH
Junos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP reset
CVSS 7.4
CVE-2026-32990 MEDIUM
Apache Tomcat: Fix for CVE-2025-66614 is incomplete
CVSS 5.3
CVE-2026-5329 HIGH
Rapid7 Velociraptor Improper Input Validation in Client Message Handler
CVSS 8.5
CVE-2026-34178 CRITICAL
Importing a crafted backup leads to project restriction bypass
CVSS 9.1
CVE-2026-5919 MEDIUM
Google Chrome <147.0.7727.55 - Auth Bypass
CVSS 6.5
CVE-2026-5915 HIGH
Google Chrome < 147.0.7727.55 - Out-of-Bounds Access
CVSS 8.1
CVE-2026-5887 MEDIUM
Google Chrome <147.0.7727.55 - Auth Bypass
CVSS 4.3
CVE-2026-5885 MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 6.5
CVE-2026-5884 HIGH
Google Chrome <147.0.7727.55 - Code Injection
CVSS 8.8
Details
Vulnerabilities 12,039
Exploit Likelihood High