VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 526 of 668
  • CVE-2026-56398HigJul 15, 2026
    risk 0.00cvss 7.3epss 0.01

    Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be…

  • CVE-2026-56349MedJul 15, 2026
    risk 0.00cvss epss 0.00

    n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity.

  • CVE-2026-47470MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-15778MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-15771MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.00

    Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security…

  • CVE-2026-15769HigJul 14, 2026
    risk 0.00cvss 8.3epss 0.00

    Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…

  • CVE-2026-62659MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings

  • CVE-2026-62658MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.

  • CVE-2026-62656MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.

  • CVE-2026-55124MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.01

    Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2026-50670HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50417HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

  • CVE-2026-50370HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-50328HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-15757MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the…

  • CVE-2026-55899HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-13699MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request contains a valid signal_id but omits data_point, the server directly…

  • CVE-2026-22102CriJul 13, 2026
    risk 0.00cvss epss 0.01

    A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification. This can be used to cause a denial of service by overwriting system files,…

  • CVE-2026-15535MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument…

  • CVE-2026-15531MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to…