CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,834 vulnerabilities with CWE-20
CVE-2026-16632 HIGH
boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation
CVSS 7.3
CVE-2026-13057 MEDIUM
Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META
CVSS 5.3
CVE-2026-46738 CRITICAL
Dell PowerProtect Data Manager < 20.2.0.0 or later - Improper Input Validation
CVSS 9.1
CVE-2026-46737 MEDIUM
Dell PowerProtect Data Manager < 20.2.0.0 or later - Improper Input Validation
CVSS 6.7
CVE-2026-40714 HIGH
Dell PowerProtect Data Manager < 20.2.0.0 or later - Improper Input Validation
CVSS 7.2
CVE-2026-40712 CRITICAL
Dell PowerProtect Data Manager < 20.2.0.0 or later - Improper Input Validation
CVSS 9.1
CVE-2026-55973 HIGH
'dns-error-reporting: yes' leads to stack buffer overflow
CVSS 7.5
CVE-2026-57600 HIGH
Hikvision DS-2CD Series - Improper Input Validation
CVSS 7.5
CVE-2026-16551 MEDIUM
Denial-of-Service in OpenCanary's MongoDB module
CVE-2026-16422 HIGH
Google Chrome - Improper Input Validation
CVSS 7.5
CVE-2026-16421 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-16415 MEDIUM
Google Chrome - Improper Input Validation
CVSS 5.4
CVE-2026-16414 HIGH
Google Chrome - Improper Input Validation
CVSS 7.8
CVE-2026-62519 MEDIUM
Oracle Succession Planning < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61160 HIGH
Oracle Commerce Guided Search / Oracle Commerce Experience Manager - Denial of Service
CVSS 8.1
CVE-2026-61079 MEDIUM
Oracle GoldenGate - Denial of Service
CVSS 5.8
CVE-2026-60719 CRITICAL
Oracle BI Publisher - Denial of Service
CVSS 9.9
CVE-2026-60650 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60648 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60640 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.3
CVE-2026-60639 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60638 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60637 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60636 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60634 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
Details
Vulnerabilities 12,834
Exploit Likelihood High