CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,440 vulnerabilities with CWE-20
CVE-2025-57805 HIGH
Scratch Channel <1.1 - Info Disclosure
CVE-2025-55301 MEDIUM
Scratch Channel <1 - Info Disclosure
CVSS 6.7
CVE-2025-52451 HIGH
Tableau Server < 2023.3.19 - Absolute Path Traversal via tabdoc API Create-Data-Source-From-File-Upload
CVSS 8.5
CVE-2025-50674 HIGH
OpenMediaVault 7.4.17 - Privilege Escalation
CVSS 7.8
CVE-2025-9288 CRITICAL
sha.js < 2.4.11 - Input Data Manipulation via Improper Input Validation
CVSS 9.1
CVE-2025-9287 CRITICAL
cipher-base <1.0.4 - Info Disclosure
CVSS 9.1
CVE-2025-55444 CRITICAL
Online Artwork & Fine Arts MCA Project 1.0 - SQL Injection
CVSS 9.8
CVE-2025-36114 MEDIUM
IBM QRadar SOAR Plugin App 1.0.0-5.6.0 - Path Traversal via URL Request
CVSS 6.5
CVE-2025-7693 CRITICAL
Rockwell Automation PLC - Micro850 L50E V20.011-V22.011 - Denial of Service via Malformed CIP Forward Close Packet
CVE-2025-6625 HIGH
Schneider Electric Modicon M340 - Denial of Service via Crafted FTP Command
CVSS 7.5
CVE-2025-52620 MEDIUM
HCL BigFix SaaS < 8.1.14 - Cross-Site Scripting via Image Upload
CVSS 4.3
CVE-2025-9060 CRITICAL
MSoft MFlash 8.0 - Authenticated Remote Code Execution via Integration Configuration
CVSS 9.1
CVE-2025-7507 MEDIUM
elink - Embed Content <= 1.1.0 - Authenticated Malicious Redirect via Shortcode URL Parameter
CVSS 6.4
CVE-2025-20148 HIGH
Cisco Secure Firewall Management Center - XSS
CVSS 8.5
CVE-2025-8876 HIGH KEV
N-able N-central < 2025.3.1 - OS Command Injection
CVSS 8.8
CVE-2025-7971 HIGH
Studio 5000 Logix Designer - Code Injection
CVE-2025-8963 MEDIUM
jeecgboot JimuReport < 2.1.1 - Deserialization of Untrusted Data via Data Large Screen Template
CVSS 6.3
CVE-2025-27388 HIGH
OPPO Health App <= 4.23.4 - WebView Arbitrary URL Token Theft
CVE-2025-4410 HIGH
InsydeH2O - Buffer Overflow in SetupUtility
CVSS 7.5
CVE-2025-4277 HIGH
InsydeH2O Kernel 5.2-5.7 - Arbitrary Memory Write and Code Execution in SMRAM via Tcg2Smm
CVSS 7.5
CVE-2025-4276 HIGH
InsydeH2O Kernel 5.3-5.7 - Arbitrary SMRAM Write and SMM Code Execution via UsbCoreDxe
CVSS 7.5
CVE-2025-49554 HIGH
Adobe Commerce < 2.4.4 - Denial of Service via Improper Input Validation
CVSS 7.5
CVE-2025-25005 MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 6.5
CVE-2025-32004 LOW
Intel Edger8r Tool - Privilege Escalation
CVSS 3.9
CVE-2025-27537 MEDIUM
Intel(R) Tiber(TM) Edge Platform <24.11.1 - Privilege Escalation
CVSS 5.5
Details
Vulnerabilities 12,440
Exploit Likelihood High