CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,448 vulnerabilities with CWE-20
CVE-2025-54641 MEDIUM
Huawei EMUI and HarmonyOS - Denial of Service via Kernel Acceleration Module Buffer Overflow
CVSS 6.7
CVE-2025-54636 MEDIUM
Huawei EMUI and HarmonyOS - Denial of Service via Kernel Drop Detection Module
CVSS 4.4
CVE-2025-54614 MEDIUM
HarmonyOS - Denial of Service via Home Screen Input Verification
CVSS 6.2
CVE-2025-8573 MEDIUM
Concrete CMS 9.0-9.4.2 - Stored Cross-Site Scripting via Home Folder on Members Dashboard
CVSS 4.8
CVE-2025-8571 MEDIUM
Concrete CMS < 8.5.21 and 9.0.0-9.4.2 - Reflected Cross-Site Scripting in Conversation Messages Dashboard Page
CVSS 4.8
CVE-2025-7674 HIGH
Roche Diagnostics navify Monitoring <1.08.00 - DoS
CVE-2025-27212 CRITICAL
UniFi Access <2.14.21-1.10.32-1.7.28 - Command Injection
CVSS 9.8
CVE-2025-27211 HIGH
EdgeMAX EdgeSwitch <1.10.4 - Command Injection
CVSS 7.5
CVE-2025-54564 HIGH
ChargePoint Home Flex <5.5.4.13 - Command Injection
CVSS 7.8
CVE-2025-30480 MEDIUM
Dell PowerProtect Data Manager <19.19 - Info Disclosure
CVSS 6.5
CVE-2025-50578 CRITICAL
LinuxServer.io heimdall 2.6.3-ls307 - Host Header Injection and Open Redirect
CVSS 9.8
CVE-2025-4424 MEDIUM
InsydeH2O < L05.05.40.011803.172079 - Improper Input Validation
CVSS 6.0
CVE-2025-43253 CRITICAL
macOS <15.6-14.7.7 - Privilege Escalation
CVSS 9.8
CVE-2025-43234 CRITICAL
iPadOS < 18.6 - Memory Corruption via Malicious Texture Processing
CVSS 9.8
CVE-2025-43223 HIGH
iPadOS < 17.7.9 - Denial of Service via Network Settings Modification
CVSS 7.5
CVE-2025-43195 MEDIUM
macOS <15.6-13.7.7 - Info Disclosure
CVSS 5.5
CVE-2025-31281 CRITICAL
iPadOS < 18.6 - Denial of Service via Maliciously Crafted File
CVSS 9.1
CVE-2025-50492 HIGH
PHPGurukul e-Diary Mgt <v1 - Session Hijacking
CVSS 7.5
CVE-2025-50489 HIGH
PHPGurukul Student Result Management System v2.0 - Info Disclosure
CVSS 7.5
CVE-2025-50494 HIGH
PHPGurukul Car Washing Mgmt <1.0 - Session Hijacking
CVSS 7.5
CVE-2025-50493 HIGH
PHPGurukul Doctor <v1 - Session Hijacking
CVSS 7.5
CVE-2025-50490 HIGH
PHPGurukul Student Result Mgt Sys <v2.0 - Session Hijacking
CVSS 7.5
CVE-2025-8266 MEDIUM
chancms < 3.1.3 - Deserialization via getArticle Function
CVSS 6.3
CVE-2025-8227 MEDIUM
chancms < 3.1.3 - Deserialization via /collect/getArticle taskUrl Parameter
CVSS 6.3
CVE-2025-8097 MEDIUM
WoodMart theme <8.2.6 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 12,448
Exploit Likelihood High