CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,834 vulnerabilities with CWE-20
CVE-2026-17655 CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
CVE-2026-17651 CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
CVE-2026-67436 HIGH
Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins
CVE-2026-54663 MEDIUM
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVSS 6.1
CVE-2026-18174 MEDIUM
@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For
CVSS 5.3
CVE-2026-65891 MEDIUM
Joomla Content Editor < 2.20.2 - Authenticated Hidden File Creation
CVSS 6.5
CVE-2026-58186 HIGH
Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses
CVSS 7.5
CVE-2026-58183 MEDIUM
Apache Traffic Server: prefetch plugin can crash on attacker-influenced input
CVSS 5.9
CVE-2026-33267 CRITICAL
Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
CVSS 10.0
CVE-2026-47219 HIGH
find-my-way is Vulnerable to DDoS with HTTP2
CVSS 7.5
CVE-2026-56722 MEDIUM
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
CVE-2026-55554 LOW
Dompdf: Chroot Validation Bypass
CVE-2026-62828 MEDIUM
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
CVSS 5.4
CVE-2026-59878 HIGH
Apache ActiveMQ AMQP - Unauthenticated NIO Denial of Service
CVSS 7.5
CVE-2026-62425 MEDIUM
buffer overruns in libfsimage iso9660 handling
CVSS 5.5
CVE-2026-43813 HIGH
Apple Ios And iPadOS - Denial of Service
CVSS 7.1
CVE-2026-43793 CRITICAL
macOS < 14.8.8, < 15.7.8, < 26.6 - Denial of Service via Environment Variable Handling
CVSS 9.8
CVE-2026-43777 HIGH
Apple macOS - Denial of Service
CVSS 7.5
CVE-2026-43714 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-54272 MEDIUM
ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
CVE-2026-46452 MEDIUM
Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure
CVSS 5.3
CVE-2026-54120 CRITICAL
Microsoft Surface Remote Code Execution Vulnerability
CVSS 9.9
CVE-2026-65604 HIGH
Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass
CVSS 8.2
CVE-2026-47668 CRITICAL
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVSS 10.0
CVE-2026-16723 CRITICAL
Remote Code Execution in fastjson 1.2.68–1.2.83
CVSS 9.0
Details
Vulnerabilities 12,834
Exploit Likelihood High