The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,834 vulnerabilities with CWE-20
CVE-2026-17655
CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
CVE-2026-17651
CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
CVE-2026-67436
HIGH
Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins
CVE-2026-54663
MEDIUM
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVSS 6.1
CVE-2026-18174
MEDIUM
@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For
CVSS 5.3
CVE-2026-65891
MEDIUM
Joomla Content Editor < 2.20.2 - Authenticated Hidden File Creation
CVSS 6.5
CVE-2026-58186
HIGH
Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses
CVSS 7.5
CVE-2026-58183
MEDIUM
Apache Traffic Server: prefetch plugin can crash on attacker-influenced input
CVSS 5.9
CVE-2026-33267
CRITICAL
Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
CVSS 10.0
CVE-2026-47219
HIGH
find-my-way is Vulnerable to DDoS with HTTP2
CVSS 7.5
CVE-2026-56722
MEDIUM
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
CVE-2026-55554
LOW
Dompdf: Chroot Validation Bypass
CVE-2026-62828
MEDIUM
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
CVSS 5.4
CVE-2026-59878
HIGH
Apache ActiveMQ AMQP - Unauthenticated NIO Denial of Service
CVSS 7.5
CVE-2026-62425
MEDIUM
buffer overruns in libfsimage iso9660 handling
CVSS 5.5
CVE-2026-43813
HIGH
Apple Ios And iPadOS - Denial of Service
CVSS 7.1
CVE-2026-43793
CRITICAL
macOS < 14.8.8, < 15.7.8, < 26.6 - Denial of Service via Environment Variable Handling
CVSS 9.8
CVE-2026-43777
HIGH
Apple macOS - Denial of Service
CVSS 7.5
CVE-2026-43714
MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-54272
MEDIUM
ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
CVE-2026-46452
MEDIUM
Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure
CVSS 5.3
CVE-2026-54120
CRITICAL
Microsoft Surface Remote Code Execution Vulnerability
CVSS 9.9
CVE-2026-65604
HIGH
Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass
CVSS 8.2
CVE-2026-47668
CRITICAL
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVSS 10.0
CVE-2026-16723
CRITICAL
Remote Code Execution in fastjson 1.2.68–1.2.83
CVSS 9.0
Details
Vulnerabilities
12,834
Exploit Likelihood
High