The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,440 vulnerabilities with CWE-20
CVE-2025-11676
HIGH
TP-Link TL-WR940N V6 <= Build 220801 - Unauthenticated Denial of Service via UPnP Input Validation
CVE-2025-63213
CRITICAL
QVidium Opera11 <2.9.0-Ax4x-opera11 - RCE
CVSS 9.8
CVE-2025-64759
HIGH
homarr < 1.43.3 - Stored Cross-Site Scripting via Malicious SVG File Upload
CVSS 8.1
CVE-2025-12842
MEDIUM
Booking Plugin for WordPress Appointments - Time Slot <= 1.4.7 - Unauthenticated Email Sending
CVSS 5.3
CVE-2025-64515
MEDIUM
Open Forms < 3.2.7 - Improper Input Validation in Prefill Data Fields
CVSS 4.3
CVE-2025-55058
MEDIUM
Maxum Rumpus - Improper Input Validation
CVSS 4.5
CVE-2025-13319
HIGH
Digi On-Prem Manager - SQL Injection
CVSS 8.8
CVE-2025-10460
CRITICAL
BEIMS Contractor Web - SQL Injection
CVE-2025-64747
MEDIUM
Directus < 11.13.0 - Stored Cross-Site Scripting via Block Editor Interface
CVSS 5.5
CVE-2025-62222
HIGH
GitHub Copilot Chat < 0.32.5 - Remote Code Execution via Command Injection
CVSS 8.8
CVE-2025-33000
HIGH
Intel QuickAssist Technology <2.6.0 - Privilege Escalation
CVSS 8.8
CVE-2025-31948
LOW
Intel(R) oneAPI Math Kernel Library <2025.2 - DoS
CVSS 3.3
CVE-2025-30509
LOW
Intel QuickAssist Technology <2.6.0 - Privilege Escalation
CVSS 3.8
CVE-2025-25216
LOW
Intel Graphics Drivers and Intel LTS kernels - Denial of Service via Improper Input Validation
CVSS 3.3
CVE-2025-24847
MEDIUM
Intel(R) CIP <WIN_DCA_2.4.0.11001 - Info Disclosure
CVSS 4.5
CVE-2025-24512
MEDIUM
Intel(R) PROSet/Wireless WiFi Software <23.160 - DoS
CVSS 5.6
CVE-2025-24299
HIGH
Intel Computing Improvement Program < 2.4.11001 - Privilege Escalation via Improper Input Validation
CVSS 8.8
CVE-2025-20056
MEDIUM
Intel VTune Profiler <2025.1 - Privilege Escalation
CVSS 4.4
CVE-2025-12944
HIGH
NETGEAR DGN2200v4 Firmware < 1.0.0.132 - Remote Code Execution
CVSS 8.8
CVE-2025-12942
HIGH
NETGEAR R6260-1.1.0.86, NETGEAR R6850-1.1.0.86 - Command Injection
CVSS 7.5
CVE-2025-63397
MEDIUM
OneFlow v0.9.0 - Denial of Service via Python Sequence in Broadcasting/Type Conversion
CVSS 6.5
CVE-2025-12908
MEDIUM
Google Chrome <140.0.7339.80 - CSRF
CVSS 5.4
CVE-2025-12907
HIGH
Google Chrome < 140.0.7339.80 - Remote Code Execution via Devtools Input Validation Bypass
CVSS 8.8
CVE-2025-63785
MEDIUM
Onlook 0.2.32 - DOM-based Cross-Site Scripting in Text Editor via innerHTML Injection
CVSS 6.1
CVE-2025-63783
HIGH
Onlook 0.2.32 - Privilege Escalation
CVSS 7.6
Details
Vulnerabilities
12,440
Exploit Likelihood
High