The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
12,834 vulnerabilities with CWE-20
CVE-2026-60633
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60620
MEDIUM
Oracle Corporation JD Edwards EnterpriseOne Configurator - Denial of Service
CVSS 6.4
CVE-2026-60526
MEDIUM
Oracle Java SE 8u491 and 8u491-perf - Local Privilege Escalation via Installation Component APIs
CVSS 6.7
CVE-2026-64877
HIGH
Tenable, Inc. Security Center < 6.8.0 - Improper Input Validation
CVSS 8.4
CVE-2026-15792
HIGH
moby BuildKit - Possible Panic When Incorrect Parameters Sent from Frontend
CVSS 7.5
CVE-2026-15724
HIGH
Path traversal in Progress ShareFile Storage Zones Controller (SZC)
CVSS 8.7
CVE-2026-16378
HIGH
Other issue in the DOM: Copy & Paste and Drag & Drop component
CVSS 7.5
CVE-2026-1771
HIGH
MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint
CVSS 7.2
CVE-2026-47255
HIGH
AgenticMail API/storage and outbound relay hardening
CVSS 8.2
CVE-2026-58624
MEDIUM
Apache MINA SSHD: Remote execution of JGit commands can write files on the server
CVSS 5.4
CVE-2026-47198
HIGH
Paymenter: URL parameter injection bypasses paid plan limits at checkout
CVSS 8.5
CVE-2026-44978
MEDIUM
xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification
CVSS 5.3
CVE-2026-35048
CRITICAL
Piwigo RCE via PHP Code Injection into Config File in Installer
CVSS 9.8
CVE-2026-63428
MEDIUM
HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field set
CVSS 5.8
CVE-2026-63734
MEDIUM
SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import
CVSS 4.9
CVE-2026-42566
HIGH
Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure
CVSS 7.5
CVE-2026-16117
CRITICAL
@fastify/http-proxy vulnerable to prefix escape via URL-encoded characters
CVSS 10.0
CVE-2026-7755
HIGH
MCP Server Configuration Validator Bypass via File Upload API
CVSS 8.8
CVE-2026-49208
MEDIUM
Symfony UX: Format-less date LiveProps parsed with the permissive DateTime constructor
CVSS 5.3
CVE-2026-53412
CRITICAL
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CVSS 9.8
CVE-2026-53411
HIGH
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CVSS 7.8
CVE-2026-44180
CRITICAL
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed
CVSS 9.8
CVE-2026-53409
HIGH
Zoom Communications Zoom Rooms < 7.1.0 - Improper Input Validation
CVSS 7.8
CVE-2026-33692
HIGH
AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration
CVSS 7.5
CVE-2026-54728
MEDIUM
bunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWeb
Details
Vulnerabilities
12,834
Exploit Likelihood
High