CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,836 vulnerabilities with CWE-20
CVE-2026-15778 MEDIUM
Google Chrome - Improper Input Validation
CVSS 6.5
CVE-2026-15771 MEDIUM
Google Chrome - Improper Input Validation
CVSS 5.3
CVE-2026-15769 HIGH
Google Chrome - Improper Input Validation
CVSS 8.3
CVE-2026-13001 CRITICAL
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
CVSS 9.8
CVE-2026-62659 MEDIUM
Authenticated users can make unauthorized changes on NETGEAR WAX333 Access Points
CVE-2026-62658 MEDIUM
NETGEAR Nighthawk RAX Routers - Authenticated Command Injection
CVE-2026-62656 MEDIUM
Post-authenticated command injection vulnerability found in certain NETGEAR RAX models
CVE-2026-55124 MEDIUM
Microsoft Word Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-50670 HIGH
Microsoft Windows 10 Version 1809 - Windows Win32k Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-50417 HIGH
Microsoft Windows 10 Version 1607 - Windows NTFS Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-50370 HIGH
Microsoft Windows 10 Version 1607 - DHCP Server Service Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-50328 HIGH
Microsoft Windows 10 Version 1607 - Windows Server Update Service (WSUS) Tampering Vulnerability
CVSS 7.5
CVE-2026-15757 MEDIUM
NETGEAR DGND3700v1 - Adjacent Network Command Injection
CVE-2026-55899 HIGH
Microsoft Excel Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-6790 MEDIUM
Eclipse Jetty - Improper Input Validation
CVSS 5.3
CVE-2026-13699 MEDIUM
Databroker 0.6.1 PublishValue missing data_point panic
CVSS 4.3
CVE-2026-22102 CRITICAL
EVbee DC-80 - Arbitrary File Overwrite Through Certificate Update Functionality
CVE-2026-15535 MEDIUM
AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization
CVSS 6.3
CVE-2026-15531 MEDIUM
yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserialization
CVSS 5.3
CVE-2026-15529 MEDIUM
yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization
CVSS 6.3
CVE-2026-3576 HIGH
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
CVSS 7.2
CVE-2026-11914 MEDIUM
Composer - Critical - Unsupported - SA-CONTRIB-2026-046
CVSS 5.9
CVE-2026-40454 HIGH
Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data
CVSS 7.5
CVE-2026-15288 HIGH
SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation
CVSS 7.5
CVE-2026-0282 MEDIUM
PAN-OS Management Web Interface - Unauthenticated File Deletion
CVSS 6.5
Details
Vulnerabilities 12,836
Exploit Likelihood High