CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 333 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21893 | Hig | 0.40 | 7.2 | 0.01 | Feb 4, 2026 | n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute… | ||
| CVE-2025-71011 | Med | 0.40 | 6.2 | 0.00 | Jan 29, 2026 | An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | ||
| CVE-2025-71009 | Med | 0.40 | 6.2 | 0.00 | Jan 29, 2026 | An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted indices. | ||
| CVE-2026-24348 | Med | 0.40 | 6.1 | 0.00 | Jan 27, 2026 | Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users. | ||
| CVE-2025-68970 | Med | 0.40 | 6.1 | 0.00 | Jan 14, 2026 | Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-68964 | Med | 0.40 | 6.2 | 0.00 | Jan 14, 2026 | Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-67163 | Med | 0.40 | 6.1 | 0.00 | Dec 18, 2025 | A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter. | ||
| CVE-2025-67170 | Med | 0.40 | 6.1 | 0.00 | Dec 17, 2025 | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload. | ||
| CVE-2025-61822 | Med | 0.40 | 6.2 | 0.01 | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to arbitrary locations on the file system.… | ||
| CVE-2025-63785 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2025 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a… | ||
| CVE-2025-12284 | Med | 0.40 | 6.1 | 0.00 | Oct 26, 2025 | Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | ||
| CVE-2025-12001 | Med | 0.40 | 6.1 | 0.00 | Oct 20, 2025 | Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | ||
| CVE-2025-10164 | Hig | 0.40 | 7.3 | 0.00 | Sep 9, 2025 | A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The… | ||
| CVE-2025-54614 | Med | 0.40 | 6.2 | 0.00 | Aug 6, 2025 | Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-5878 | Hig | 0.40 | 7.3 | 0.00 | Jun 29, 2025 | A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads to an improper neutralization of special elements. The attack may be initiated remotely and an… | ||
| CVE-2025-27131 | Med | 0.40 | 6.1 | 0.00 | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. | ||
| CVE-2025-29955 | Med | 0.40 | 6.2 | 0.01 | May 13, 2025 | Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. | ||
| CVE-2025-3837 | Med | 0.40 | — | 0.00 | Apr 21, 2025 | An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till… | ||
| CVE-2025-0178 | Med | 0.40 | 6.1 | 0.00 | Feb 14, 2025 | An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites,… | ||
| CVE-2024-39606 | Med | 0.40 | 6.1 | 0.00 | Feb 12, 2025 | Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access. |
- risk 0.40cvss 7.2epss 0.01
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute…
- risk 0.40cvss 6.2epss 0.00
An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- risk 0.40cvss 6.2epss 0.00
An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted indices.
- risk 0.40cvss 6.1epss 0.00
Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.
- risk 0.40cvss 6.1epss 0.00
Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 6.1epss 0.00
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.
- risk 0.40cvss 6.1epss 0.00
A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload.
- risk 0.40cvss 6.2epss 0.01
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to arbitrary locations on the file system.…
- risk 0.40cvss 6.1epss 0.00
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a…
- risk 0.40cvss 6.1epss 0.00
Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- risk 0.40cvss 6.1epss 0.00
Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- risk 0.40cvss 7.3epss 0.00
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The…
- risk 0.40cvss 6.2epss 0.00
Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 7.3epss 0.00
A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads to an improper neutralization of special elements. The attack may be initiated remotely and an…
- risk 0.40cvss 6.1epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
- risk 0.40cvss 6.2epss 0.01
Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.
- risk 0.40cvss —epss 0.00
An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till…
- risk 0.40cvss 6.1epss 0.00
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites,…
- risk 0.40cvss 6.1epss 0.00
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.