CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,440 vulnerabilities with CWE-20
CVE-2025-8007 MEDIUM
Rockwell Automation 1756-EN2TR/EN4TR <7.001 DoS via Concurrent Forward Close
CVSS 6.5
CVE-2025-10061 MEDIUM
MongoDB 6.0.0-6.0.24 - Authenticated Denial of Service via $group Accumulator Function
CVSS 6.5
CVE-2025-58361 CRITICAL
promptcraft-forge-studio - Cross-Site Scripting via Incomplete URL Scheme Validation
CVSS 9.3
CVE-2025-58353 HIGH
promptcraft-forge-studio - Cross-Site Scripting via Regex Blacklist Bypass
CVSS 8.2
CVE-2025-32322 HIGH
Android - Unauthorized Screen Recording Token Grant via MediaProjectionPermissionActivity Input Validation
CVSS 7.8
CVE-2025-48559 MEDIUM
Android - Local Denial of Service via AppOpsService Input Validation
CVSS 5.5
CVE-2025-48556 HIGH
Android - Local Privilege Escalation via NotificationChannel Input Validation
CVSS 7.3
CVE-2025-48541 HIGH
FaceSettings < - Privilege Escalation
CVSS 7.8
CVE-2025-48538 MEDIUM
Android - Local Denial of Service via PackageManagerService Input Validation
CVSS 5.5
CVE-2025-48537 HIGH
Android - Denial of Service and Local Information Disclosure via Improper Input Validation
CVSS 7.1
CVE-2025-32323 HIGH
Android - Local Privilege Escalation via Deceptive Permission Popup Text
CVSS 7.8
CVE-2025-26429 MEDIUM
Android - Denial of Service via AppOpsService collectOps Input Validation
CVSS 5.5
CVE-2025-26426 MEDIUM
Android - Local Privilege Escalation via BroadcastController.java Input Validation
CVSS 5.1
CVE-2025-9467 MEDIUM
Vaadin <7.7.47, <8.28.1, <14.13.0, <23.6.1, <24.7 - Auth Bypass
CVE-2025-46047 MEDIUM
Silverpeas 6.4.1-6.4.2 - User Enumeration via ForgotPassword Login Parameter
CVSS 6.5
CVE-2025-52547 HIGH
Copeland E3 Supervisory Controller Firmware < 2.31f01 - Denial of Service via Unvalidated API Call
CVSS 7.5
CVE-2025-52544 HIGH
Copeland E3 Supervisory Controller Firmware < 2.31f01 - Unauthenticated Arbitrary File Read via Floor Plan Upload
CVSS 7.5
CVE-2025-8662 MEDIUM
OpenAM 14.0.0-14.0.1 - SAML IdP Malfunction via Tampered Request
CVSS 4.3
CVE-2025-55173 MEDIUM
Next.js <14.2.31, 15.0.0-15.4.4 - Code Injection
CVSS 4.3
CVE-2025-57220 MEDIUM
Tenda AC10 v4.0 Firmware 16.03.10.09_multi_TDE01 - Unauthenticated Privilege Escalation via UDP Packet to ate Service
CVSS 5.3
CVE-2025-9195 MEDIUM
Solidigm D7-PS1010/D7-PS1030 - Denial of Service via Improper Input Validation
CVSS 4.4
CVE-2025-34161 HIGH
Coolify < 4.0.0-beta.420.7 - Authenticated Remote Code Execution via Git Repository Field
CVSS 8.8
CVE-2025-34159 HIGH
Coolify < 4.0.0-beta.420.6 - Authenticated Remote Code Execution via Docker Compose Directive Injection
CVSS 8.8
CVE-2025-34157 CRITICAL
Coolify < 4.0.0-beta.420.6 - Authenticated Stored Cross-Site Scripting in Project Name
CVSS 9.0
CVE-2025-57810 HIGH
jspdf < 3.0.2 - Denial of Service via addImage Method
CVSS 7.5
Details
Vulnerabilities 12,440
Exploit Likelihood High