The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,440 vulnerabilities with CWE-20
CVE-2025-22432
MEDIUM
Android - Local Privilege Escalation via CallRedirectionProcessor Input Validation
CVSS 6.7
CVE-2025-26489
MEDIUM
Infinera MTC-9 Firmware 22.1.1.0275-<23.0 - Authenticated Denial of Service via Netconf XML Payload
CVSS 6.5
CVE-2025-26488
HIGH
Infinera MTC-9 Firmware >=22.1.1.0275 <23.0 - Unauthenticated Denial of Service via Crafted XML Payloads
CVSS 7.5
CVE-2025-54306
HIGH
Thermo Fisher Torrent Suite 5.18.1 - Authenticated Remote Code Execution via Network Configuration Endpoint
CVSS 7.2
CVE-2025-20389
MEDIUM
Splunk Enterprise <10.0.2,9.4.6,9.3.8,9.2.10 - DoS
CVSS 4.3
CVE-2025-66400
MEDIUM
mdast-util-to-hast <13.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-63095
MEDIUM
Tempus Ex hello-video-codec <0.1.0 - DoS
CVSS 6.5
CVE-2025-26858
HIGH
Socomec DIRIS Digiware M-70 1.6.9 - Unauthenticated Denial of Service via Modbus TCP
CVSS 8.6
CVE-2025-13805
LOW
NutzBoot < 2.6.0-SNAPSHOT - Remote Code Execution via LiteRpc-Serializer Deserialization
CVSS 3.7
CVE-2025-66225
HIGH
OrangeHRM 5.0-5.7 - Unauthenticated Account Takeover via Password Reset Username Manipulation
CVSS 8.8
CVE-2025-53939
MEDIUM
Kiteworks <9.1.0 - Privilege Escalation
CVSS 6.3
CVE-2025-66201
HIGH
LibreChat < 0.8.1-rc2 - Authenticated Server-Side Request Forgery via Actions Feature
CVSS 8.1
CVE-2025-13762
MEDIUM
CyberArk Secure Web Sessions Extension <2.2.30305 - DoS
CVE-2025-0658
HIGH
Automated Logic and Carrier Zone Controllers < 6.06-101 - Denial of Service via BACnet Protocol
CVE-2025-66259
CRITICAL
DB Electronica Mozart FM Transmitter - Authenticated RCE via Improper Input Validation
CVSS 9.8
CVE-2025-33191
MEDIUM
NVIDIA DGX Spark GB10 - Memory Corruption
CVSS 5.7
CVE-2025-0248
HIGH
HCL iNotes <12.0.2 FP6 and <14.0 FP4 - Reflected Cross-Site Scripting
CVSS 8.1
CVE-2025-12741
HIGH
Looker - Command Injection
CVE-2025-12740
HIGH
Looker <upgrade - Command Injection
CVE-2025-12889
MEDIUM
wolfssl - Improper Input Validation in TLS 1.2 Digest Handling
CVSS 5.4
CVE-2025-65946
HIGH
Roo Code <3.26.7 - Command Injection
CVSS 8.1
CVE-2025-11936
MEDIUM
wolfssl 5.8.2-5.8.3 - Unauthenticated Denial of Service via TLS 1.3 KeyShareEntry Parsing
CVSS 5.3
CVE-2025-11934
LOW
wolfSSL 5.8.2-5.8.4 - TLS 1.3 CertificateVerify Signature Algorithm Downgrade
CVSS 2.7
CVE-2025-11933
MEDIUM
wolfssl 5.8.2-5.8.4 - Unauthenticated Denial of Service via TLS 1.3 CKS Extension Parsing
CVSS 6.5
CVE-2025-62164
HIGH
vLLM 0.10.2-0.11.1 - Remote Code Execution via Malicious Prompt Embedding Tensors
CVSS 8.8
Details
Vulnerabilities
12,440
Exploit Likelihood
High