CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,039 vulnerabilities with CWE-20
CVE-2026-23489 CRITICAL
Fields GLPI plugin vulnerable to RCE in dropdown generation
CVSS 9.1
CVE-2026-22204 LOW
wpDiscuz <7.6.47 - Email Header Injection
CVSS 3.7
CVE-2026-1668 CRITICAL
Input Validation Vulnerability on Multiple Omada Switches
CVSS 9.8
CVE-2026-3967 MEDIUM
Alfresco Activiti <7.19/8.8.0 - Deserialization
CVSS 6.3
CVE-2026-31900 CRITICAL
Black GitHub Action - Command Injection
CVSS 9.8
CVE-2026-30901 HIGH
Zoom Rooms <6.6.5 - Privilege Escalation
CVSS 7.0
CVE-2026-21310 MEDIUM
Adobe Commerce <=2.4.9-alpha3 - Auth Bypass
CVSS 5.3
CVE-2026-21282 MEDIUM
Adobe Commerce <=2.4.9-alpha3 - DoS
CVSS 5.3
CVE-2026-26310 MEDIUM
Envoy <1.37.1/1.36.5/1.35.8/1.34.13 - DoS
CVSS 5.9
CVE-2026-26121 HIGH
Azure IoT Explorer - SSRF
CVSS 7.5
CVE-2026-26106 HIGH
Microsoft Office SharePoint - RCE
CVSS 8.8
CVE-2026-20967 HIGH
System Center Operations Manager - Privilege Escalation
CVSS 8.8
CVE-2026-3288 HIGH
ingress-nginx - Code Injection
CVSS 8.8
CVE-2026-24713 CRITICAL
Apache IoTDB 1.0.0-1.3.6/2.0.0-2.0.6 - Input Validation
CVSS 9.8
CVE-2026-29791 MEDIUM
Agentgateway <0.12.0 - Command Injection
CVSS 4.9
CVE-2026-29046 HIGH
TinyWeb <2.04 - Command Injection
CVSS 8.2
CVE-2026-0848 CRITICAL
NLTK <=3.9.2 - Code Injection
CVSS 10.0
CVE-2026-3545 CRITICAL
Google Chrome <145.0.7632.159 - Sandbox Escape
CVSS 9.6
CVE-2026-20020 MEDIUM
Cisco Secure Firewall ASA/FTD - DoS
CVSS 6.8
CVE-2026-27443 HIGH
SEPPmail Secure Email Gateway <15.0.1 - Auth Bypass
CVSS 7.5
CVE-2026-3204 CRITICAL
Devolutions Server <2025.3.15 - Info Disclosure
CVSS 9.8
CVE-2026-2590 CRITICAL
Devolutions Remote Desktop Manager <=2025.3.30 - Auth Bypass
CVSS 9.8
CVE-2026-0034 HIGH
ManagedServices.java - Privilege Escalation
CVSS 8.4
CVE-2026-0015 MEDIUM
AppOpsService.java - DoS
CVSS 6.2
CVE-2026-0014 MEDIUM
AppOpsService - DoS
CVSS 6.2
Details
Vulnerabilities 12,039
Exploit Likelihood High