The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,440 vulnerabilities with CWE-20
CVE-2025-8007
MEDIUM
Rockwell Automation 1756-EN2TR/EN4TR <7.001 DoS via Concurrent Forward Close
CVSS 6.5
CVE-2025-10061
MEDIUM
MongoDB 6.0.0-6.0.24 - Authenticated Denial of Service via $group Accumulator Function
CVSS 6.5
CVE-2025-58361
CRITICAL
promptcraft-forge-studio - Cross-Site Scripting via Incomplete URL Scheme Validation
CVSS 9.3
CVE-2025-58353
HIGH
promptcraft-forge-studio - Cross-Site Scripting via Regex Blacklist Bypass
CVSS 8.2
CVE-2025-32322
HIGH
Android - Unauthorized Screen Recording Token Grant via MediaProjectionPermissionActivity Input Validation
CVSS 7.8
CVE-2025-48559
MEDIUM
Android - Local Denial of Service via AppOpsService Input Validation
CVSS 5.5
CVE-2025-48556
HIGH
Android - Local Privilege Escalation via NotificationChannel Input Validation
CVSS 7.3
CVE-2025-48541
HIGH
FaceSettings < - Privilege Escalation
CVSS 7.8
CVE-2025-48538
MEDIUM
Android - Local Denial of Service via PackageManagerService Input Validation
CVSS 5.5
CVE-2025-48537
HIGH
Android - Denial of Service and Local Information Disclosure via Improper Input Validation
CVSS 7.1
CVE-2025-32323
HIGH
Android - Local Privilege Escalation via Deceptive Permission Popup Text
CVSS 7.8
CVE-2025-26429
MEDIUM
Android - Denial of Service via AppOpsService collectOps Input Validation
CVSS 5.5
CVE-2025-26426
MEDIUM
Android - Local Privilege Escalation via BroadcastController.java Input Validation
CVSS 5.1
CVE-2025-9467
MEDIUM
Vaadin <7.7.47, <8.28.1, <14.13.0, <23.6.1, <24.7 - Auth Bypass
CVE-2025-46047
MEDIUM
Silverpeas 6.4.1-6.4.2 - User Enumeration via ForgotPassword Login Parameter
CVSS 6.5
CVE-2025-52547
HIGH
Copeland E3 Supervisory Controller Firmware < 2.31f01 - Denial of Service via Unvalidated API Call
CVSS 7.5
CVE-2025-52544
HIGH
Copeland E3 Supervisory Controller Firmware < 2.31f01 - Unauthenticated Arbitrary File Read via Floor Plan Upload
CVSS 7.5
CVE-2025-8662
MEDIUM
OpenAM 14.0.0-14.0.1 - SAML IdP Malfunction via Tampered Request
CVSS 4.3
CVE-2025-55173
MEDIUM
Next.js <14.2.31, 15.0.0-15.4.4 - Code Injection
CVSS 4.3
CVE-2025-57220
MEDIUM
Tenda AC10 v4.0 Firmware 16.03.10.09_multi_TDE01 - Unauthenticated Privilege Escalation via UDP Packet to ate Service
CVSS 5.3
CVE-2025-9195
MEDIUM
Solidigm D7-PS1010/D7-PS1030 - Denial of Service via Improper Input Validation
CVSS 4.4
CVE-2025-34161
HIGH
Coolify < 4.0.0-beta.420.7 - Authenticated Remote Code Execution via Git Repository Field
CVSS 8.8
CVE-2025-34159
HIGH
Coolify < 4.0.0-beta.420.6 - Authenticated Remote Code Execution via Docker Compose Directive Injection
CVSS 8.8
CVE-2025-34157
CRITICAL
Coolify < 4.0.0-beta.420.6 - Authenticated Stored Cross-Site Scripting in Project Name
CVSS 9.0
CVE-2025-57810
HIGH
jspdf < 3.0.2 - Denial of Service via addImage Method
CVSS 7.5
Details
Vulnerabilities
12,440
Exploit Likelihood
High