CWE-20

High likelihood

Improper Input Validation

Parent: CWE-707 - Improper Neutralization

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

12,039 vulnerabilities with CWE-20
CVE-2026-2555 MEDIUM
JeecgBoot 3.9.1 - Deserialization
CVSS 5.0
CVE-2026-2391 LOW
qs - DoS
CVSS 3.7
CVE-2026-20627 MEDIUM
Apple <26.3 - Info Disclosure
CVSS 5.5
CVE-2026-21258 MEDIUM
Microsoft Office Excel - Info Disclosure
CVSS 5.5
CVE-2026-21247 HIGH
Windows Hyper-V - Code Injection
CVSS 7.3
CVE-2026-21229 HIGH
Power BI - Code Injection
CVSS 8.0
CVE-2026-25892 HIGH
Vrana Adminer < 5.4.2 - Improper Input Validation
CVSS 7.5
CVE-2026-2113 HIGH
yuan1994 tpadmin <1.3.12 - Deserialization
CVSS 7.3
CVE-2026-25631 MEDIUM
NPM N8n < 1.121.0 - Improper Input Validation
CVSS 6.5
CVE-2026-25723 MEDIUM
Anthropic Claude Code < 2.0.55 - OS Command Injection
CVSS 6.5
CVE-2026-25722 CRITICAL
Anthropic Claude Code < 2.0.57 - OS Command Injection
CVSS 9.1
CVE-2026-25514 HIGH
Facturascripts < 2025.81 - SQL Injection
CVSS 8.8
CVE-2026-25513 HIGH
Facturascripts < 2025.81 - SQL Injection
CVSS 8.8
CVE-2026-21893 HIGH
NPM N8n < 1.120.3 - OS Command Injection
CVSS 7.2
CVE-2026-24512 HIGH
Ingress-Nginx - RCE
CVSS 8.8
CVE-2026-1580 HIGH
K8s.io Ingress-nginx < 1.13.7 - Improper Input Validation
CVSS 8.8
CVE-2026-22220 MEDIUM
Tp-link Archer Be230 Firmware < 1.2.4 - Improper Input Validation
CVSS 4.5
CVE-2026-24936 CRITICAL
ADM <4.3.3.ROF1, <5.1.1.RCI1 - RCE
CVSS 9.8
CVE-2026-1691 MEDIUM
Bolo-Solo <2.6.4 - Deserialization
CVSS 6.3
CVE-2026-25128 HIGH
NPM Fast-xml-parser < 5.3.4 - Improper Input Validation
CVSS 7.5
CVE-2026-25126 HIGH
PolarLearn <0-PRERELEASE-15 - Info Disclosure
CVSS 7.1
CVE-2026-25117 HIGH
pwn.college DOJO <e33da14449a5abcff507e554f66e2141d6683b0a - XSS
CVE-2026-23571 MEDIUM
TeamViewer DEX - Command Injection
CVSS 6.8
CVE-2026-23570 MEDIUM
TeamViewer DEX Client <26.1 - Info Disclosure
CVSS 6.5
CVE-2026-23566 MEDIUM
TeamViewer DEX Client <26.1 - Log Injection
CVSS 6.5
Details
Vulnerabilities 12,039
Exploit Likelihood High