CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,440 vulnerabilities with CWE-20
CVE-2025-22432 MEDIUM
Android - Local Privilege Escalation via CallRedirectionProcessor Input Validation
CVSS 6.7
CVE-2025-26489 MEDIUM
Infinera MTC-9 Firmware 22.1.1.0275-<23.0 - Authenticated Denial of Service via Netconf XML Payload
CVSS 6.5
CVE-2025-26488 HIGH
Infinera MTC-9 Firmware >=22.1.1.0275 <23.0 - Unauthenticated Denial of Service via Crafted XML Payloads
CVSS 7.5
CVE-2025-54306 HIGH
Thermo Fisher Torrent Suite 5.18.1 - Authenticated Remote Code Execution via Network Configuration Endpoint
CVSS 7.2
CVE-2025-20389 MEDIUM
Splunk Enterprise <10.0.2,9.4.6,9.3.8,9.2.10 - DoS
CVSS 4.3
CVE-2025-66400 MEDIUM
mdast-util-to-hast <13.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-63095 MEDIUM
Tempus Ex hello-video-codec <0.1.0 - DoS
CVSS 6.5
CVE-2025-26858 HIGH
Socomec DIRIS Digiware M-70 1.6.9 - Unauthenticated Denial of Service via Modbus TCP
CVSS 8.6
CVE-2025-13805 LOW
NutzBoot < 2.6.0-SNAPSHOT - Remote Code Execution via LiteRpc-Serializer Deserialization
CVSS 3.7
CVE-2025-66225 HIGH
OrangeHRM 5.0-5.7 - Unauthenticated Account Takeover via Password Reset Username Manipulation
CVSS 8.8
CVE-2025-53939 MEDIUM
Kiteworks <9.1.0 - Privilege Escalation
CVSS 6.3
CVE-2025-66201 HIGH
LibreChat < 0.8.1-rc2 - Authenticated Server-Side Request Forgery via Actions Feature
CVSS 8.1
CVE-2025-13762 MEDIUM
CyberArk Secure Web Sessions Extension <2.2.30305 - DoS
CVE-2025-0658 HIGH
Automated Logic and Carrier Zone Controllers < 6.06-101 - Denial of Service via BACnet Protocol
CVE-2025-66259 CRITICAL
DB Electronica Mozart FM Transmitter - Authenticated RCE via Improper Input Validation
CVSS 9.8
CVE-2025-33191 MEDIUM
NVIDIA DGX Spark GB10 - Memory Corruption
CVSS 5.7
CVE-2025-0248 HIGH
HCL iNotes <12.0.2 FP6 and <14.0 FP4 - Reflected Cross-Site Scripting
CVSS 8.1
CVE-2025-12741 HIGH
Looker - Command Injection
CVE-2025-12740 HIGH
Looker <upgrade - Command Injection
CVE-2025-12889 MEDIUM
wolfssl - Improper Input Validation in TLS 1.2 Digest Handling
CVSS 5.4
CVE-2025-65946 HIGH
Roo Code <3.26.7 - Command Injection
CVSS 8.1
CVE-2025-11936 MEDIUM
wolfssl 5.8.2-5.8.3 - Unauthenticated Denial of Service via TLS 1.3 KeyShareEntry Parsing
CVSS 5.3
CVE-2025-11934 LOW
wolfSSL 5.8.2-5.8.4 - TLS 1.3 CertificateVerify Signature Algorithm Downgrade
CVSS 2.7
CVE-2025-11933 MEDIUM
wolfssl 5.8.2-5.8.4 - Unauthenticated Denial of Service via TLS 1.3 CKS Extension Parsing
CVSS 6.5
CVE-2025-62164 HIGH
vLLM 0.10.2-0.11.1 - Remote Code Execution via Malicious Prompt Embedding Tensors
CVSS 8.8
Details
Vulnerabilities 12,440
Exploit Likelihood High