CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,834 vulnerabilities with CWE-20
CVE-2026-60633 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60620 MEDIUM
Oracle Corporation JD Edwards EnterpriseOne Configurator - Denial of Service
CVSS 6.4
CVE-2026-60526 MEDIUM
Oracle Java SE 8u491 and 8u491-perf - Local Privilege Escalation via Installation Component APIs
CVSS 6.7
CVE-2026-64877 HIGH
Tenable, Inc. Security Center < 6.8.0 - Improper Input Validation
CVSS 8.4
CVE-2026-15792 HIGH
moby BuildKit - Possible Panic When Incorrect Parameters Sent from Frontend
CVSS 7.5
CVE-2026-15724 HIGH
Path traversal in Progress ShareFile Storage Zones Controller (SZC)
CVSS 8.7
CVE-2026-16378 HIGH
Other issue in the DOM: Copy & Paste and Drag & Drop component
CVSS 7.5
CVE-2026-1771 HIGH
MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint
CVSS 7.2
CVE-2026-47255 HIGH
AgenticMail API/storage and outbound relay hardening
CVSS 8.2
CVE-2026-58624 MEDIUM
Apache MINA SSHD: Remote execution of JGit commands can write files on the server
CVSS 5.4
CVE-2026-47198 HIGH
Paymenter: URL parameter injection bypasses paid plan limits at checkout
CVSS 8.5
CVE-2026-44978 MEDIUM
xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification
CVSS 5.3
CVE-2026-35048 CRITICAL
Piwigo RCE via PHP Code Injection into Config File in Installer
CVSS 9.8
CVE-2026-63428 MEDIUM
HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field set
CVSS 5.8
CVE-2026-63734 MEDIUM
SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import
CVSS 4.9
CVE-2026-42566 HIGH
Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure
CVSS 7.5
CVE-2026-16117 CRITICAL
@fastify/http-proxy vulnerable to prefix escape via URL-encoded characters
CVSS 10.0
CVE-2026-7755 HIGH
MCP Server Configuration Validator Bypass via File Upload API
CVSS 8.8
CVE-2026-49208 MEDIUM
Symfony UX: Format-less date LiveProps parsed with the permissive DateTime constructor
CVSS 5.3
CVE-2026-53412 CRITICAL
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CVSS 9.8
CVE-2026-53411 HIGH
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CVSS 7.8
CVE-2026-44180 CRITICAL
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed
CVSS 9.8
CVE-2026-53409 HIGH
Zoom Communications Zoom Rooms < 7.1.0 - Improper Input Validation
CVSS 7.8
CVE-2026-33692 HIGH
AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration
CVSS 7.5
CVE-2026-54728 MEDIUM
bunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWeb
Details
Vulnerabilities 12,834
Exploit Likelihood High