CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,449 vulnerabilities with CWE-20
CVE-2025-20031 MEDIUM
Intel(R) Graphics Drivers - Authenticated Denial of Service via Improper Input Validation
CVSS 6.5
CVE-2025-20009 MEDIUM
Intel(R) Server D50DNP/M50FCP - Info Disclosure
CVSS 4.1
CVE-2025-32706 HIGH KEV
Windows Common Log File System Driver - Authenticated Privilege Escalation via Improper Input Validation
CVSS 7.8
CVE-2025-29968 MEDIUM
Active Directory Certificate Services - DoS
CVSS 6.5
CVE-2025-29955 MEDIUM
Windows 11 24H2 and Windows Server 2022 23H2 and Windows Server 2025 - Denial of Service via Improper Input Validation
CVSS 6.2
CVE-2025-40556 MEDIUM
Siemens BACnet ATEC 550-440, 550-441, 550-445, 550-446 - Denial of Service via BACnet MSTP Message
CVSS 6.5
CVE-2025-24510 MEDIUM
Siemens MS/TP Point Pickup Module - Denial of Service via BACnet MSTP Message Handling
CVSS 6.5
CVE-2025-31259 HIGH
macOS < 15.5, <14.8, <26 - Unprotected User Data Exposure via Screenshot Capture
CVSS 7.8
CVE-2025-31240 HIGH
macOS < 13.7.6, < 14.7.6, < 15.5 - Denial of Service via Malicious AFP Network Share
CVSS 7.5
CVE-2025-31233 MEDIUM
iPadOS < 17.7.7 - Denial of Service via Maliciously Crafted Video File
CVSS 6.3
CVE-2025-31217 MEDIUM
Safari < 18.5 - Denial of Service via Malicious Web Content
CVSS 6.5
CVE-2025-31215 MEDIUM
Safari < 18.5 - Denial of Service via Malicious Web Content
CVSS 6.5
CVE-2025-31208 HIGH
iPadOS < 17.7.7 - Denial of Service via File Parsing
CVSS 7.5
CVE-2025-30442 HIGH
macOS < 13.7.6, < 14.7.6, < 15.4 - Privilege Escalation
CVSS 7.8
CVE-2025-24274 HIGH
macOS < 13.7.6, < 14.7.6, < 15.5 - Privilege Escalation to Root
CVSS 7.8
CVE-2025-1087 CRITICAL
Kong Insomnia Desktop Application <11.0.2 - Code Injection
CVE-2025-4377 HIGH
Sparx Systems Pro Cloud Server <6.0.165 - Path Traversal
CVE-2025-4376 MEDIUM
Sparx Systems Pro Cloud Server <6.0.165 - XSS
CVE-2025-40846 HIGH
Halo <2.174.101, 2.175.1-2.184.21 - Open Redirect
CVE-2025-20197 MEDIUM
Cisco IOS XE Software - Privilege Escalation
CVSS 6.7
CVE-2025-20154 HIGH
Cisco IOS XR - Unauthenticated Denial of Service via TWAMP Control Packet Processing
CVSS 8.6
CVE-2025-21460 HIGH
Qualcomm QAM and SA Series Firmware - Memory Corruption via Guest VM Buffer Manipulation
CVSS 7.8
CVE-2025-46340 HIGH
Misskey 12.0.0-2025.4.1 - CSS Injection via UrlPreviewService and MkUrlPreview
CVSS 7.2
CVE-2025-4260 MEDIUM
zhangyanbo2007 youkefu <4.2.0 - Deserialization
CVSS 4.3
CVE-2025-30391 HIGH
Microsoft Dynamics - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 12,449
Exploit Likelihood High