CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,440 vulnerabilities with CWE-20
CVE-2025-65561 HIGH
free5gc 4.1.0 - Denial of Service via PFCP Session Modification Request Local SEID Header
CVSS 7.5
CVE-2025-67493 HIGH
homarr < 1.45.3 - Authenticated Privilege Escalation via LDAP Query Injection
CVSS 7.5
CVE-2025-43533 MEDIUM
iPadOS < 26.2 - Denial of Service via Malicious HID Device
CVSS 5.7
CVE-2025-67170 MEDIUM
RiteCMS 3.1.0 - Reflected Cross-Site Scripting
CVSS 6.1
CVE-2025-66923 HIGH
Open Source Point of Sale 3.4.1 - Stored Cross-Site Scripting via Phone Number Parameter
CVSS 7.2
CVE-2025-66921 HIGH
Open Source Point of Sale 3.4.1 - Stored Cross-Site Scripting via Item Name Parameter
CVSS 7.2
CVE-2025-20393 CRITICAL KEV
Cisco AsyncOS < 15.0.5-016 - Unauthenticated Remote Code Execution via Spam Quarantine HTTP Request
CVSS 10.0
CVE-2025-58173 HIGH
FreshRSS 1.23.0-1.27.0 - Unauthenticated Path Traversal via Language Parameter
CVSS 8.8
CVE-2025-14156 CRITICAL
Fox LMS - WordPress LMS Plugin <1.0.5.1 - Privilege Escalation
CVSS 9.8
CVE-2025-9207 MEDIUM
TI WooCommerce Wishlist <2.10.0 - XSS
CVSS 5.3
CVE-2025-14606 MEDIUM
Tiny RDM <= 1.2.5 - Remote Code Execution via Pickle Deserialization
CVSS 5.0
CVE-2025-43494 HIGH
iPadOS < 18.7.2 - Persistent Denial-of-Service via Mail Header Parsing
CVSS 7.5
CVE-2025-43482 MEDIUM
macOS < 14.8.3, < 15.7.3, < 26.2 - Denial of Service
CVSS 5.5
CVE-2025-43464 MEDIUM
macOS < 26.1 - Denial of Service via Website Visit
CVSS 6.5
CVE-2025-66451 MEDIUM
LibreChat < 0.8.1 - Improperly Controlled Modification of Dynamically-Determined Object Attributes via PATCH Endpoint
CVSS 6.5
CVE-2025-36932 HIGH
Android - Local Privilege Escalation via Improper Input Validation in tracepoint_msg_handler
CVSS 7.8
CVE-2025-36929 MEDIUM
Android - Local Information Disclosure via AreFencesRegistered Input Validation
CVSS 5.5
CVE-2025-66918 HIGH
edoc-doctor-appointment-system 1.0.1 - Cross-Site Scripting via Title Parameter
CVSS 8.8
CVE-2025-64993 MEDIUM
TeamViewer DEX < 29.0 - Authenticated Command Injection via 1E-ConfigMgrConsoleExtensions
CVSS 6.8
CVE-2025-64992 MEDIUM
TeamViewer DEX < 25.0 - Authenticated Command Injection via 1E-Nomad-PauseNomadJobQueue
CVSS 6.8
CVE-2025-64991 MEDIUM
TeamViewer DEX < 15.0 - Authenticated Command Injection via 1E-PatchInsights-Deploy Instruction
CVSS 6.8
CVE-2025-64990 MEDIUM
TeamViewer DEX < 21.1 - Authenticated Command Injection via 1E-Explorer-TachyonCore-LogoffUser Instruction
CVSS 6.8
CVE-2025-64989 HIGH
TeamViewer DEX < 21.1 - Authenticated Command Injection via 1E-Explorer-TachyonCore-FindFileBySizeAndHash
CVSS 7.2
CVE-2025-64988 HIGH
TeamViewer DEX < 19.2 - Authenticated Command Injection via 1E-Nomad-GetCmContentLocations Instruction
CVSS 7.2
CVE-2025-64987 HIGH
TeamViewer DEX < 21.0 - Authenticated Command Injection via 1E-Explorer-TachyonCore-CheckSimpleIoC
CVSS 7.2
Details
Vulnerabilities 12,440
Exploit Likelihood High