VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-27306High· 8.4
5mo ago

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitat…

▾ Twilightadobe · coldfusionEPSS 0.48%via NVD
CVE-2026-27304Critical· 9.3
5mo ago

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…

▾ Midnightadobe · coldfusionEPSS 0.46%via NVD
CVE-2026-27282High· 7.5
5mo ago

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…

▾ Twilightadobe · coldfusionEPSS 0.79%via NVD
CVE-2026-24893High· 8.8
5mo ago

openITCOCKPIT is an open source monitoring tool built for different monitoring engines

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission t…

▾ Twilightit-novum · openitcockpitEPSS 1.4%via NVD
CVE-2026-33116High· 7.5
5mo ago

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · .netEPSS 2.4%via NVD
CVE-2026-56762Medium· 5.3
5mo ago

Hono missing validation of cookie name on write path in setCookie()

Hono missing validation of cookie name on write path in setCookie()

▾ Sunlithono · honoEPSS 0.42%via GHSA
CVE-2026-5919Medium· 6.5
5mo ago

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security …

▾ Sunlitgoogle · chromeEPSS 0.30%via NVD
CVE-2026-5915High· 8.1
5mo ago

Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page

Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-5887Medium· 4.3
5mo ago

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to bypass download restrictions via a crafted HTML page

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-5885Medium· 6.5
5mo ago

Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page

Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security …

▾ Sunlitgoogle · chromeEPSS 0.30%via NVD
CVE-2026-5884High· 8.8
5mo ago

Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page

Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium …

▾ Twilightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-5879High· 8.8
5mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-34197High· 8.8CISA KEVPoC
5mo ago

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

▾ Abyssalapache · activemqEPSS 15%via NVD
CVE-2025-48651Medium· 5.5
5mo ago

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2020-37216High· 7.5
5mo ago

Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device

Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attack…

▾ TwilightEPSS 0.92%via NVD
CVE-2026-35038Medium· 6.5
5mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated u…

▾ Sunlitsignalk · signal_k_serverEPSS 0.41%via NVD
CVE-2026-20097Medium· 6.5
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validatio…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validatio…

▾ Sunlitcisco · unified_computing_systemEPSS 0.39%via NVD
CVE-2026-34442Medium· 5.4
6mo ago

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary do…

▾ Sunlitfreescout · freescoutEPSS 0.32%via NVD
CVE-2025-14213None
6mo ago

Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on th…

Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on th…

▾ SunlitEPSS 0.98%via NVD
CVE-2026-21712Medium· 6.5
6mo ago

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

▾ Sunlitnodejs · node.jsEPSS 0.32%via NVD
CVE-2026-33894High· 7.5PoC
6mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attack…

▾ Midnightdigitalbazaar · forgeEPSS 0.45%via NVD
CVE-2026-33218High· 7.5
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed mess…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.84%via NVD
CVE-2026-4519Low· 3.3
6mo ago

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to …

▾ Sunlitpython · pythonEPSS 0.39%via NVD
CVE-2026-3644High· 7.5
6mo ago

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additio…

▾ Twilightpython · pythonEPSS 0.65%via NVD
CVE-2025-13462Low· 3.3
6mo ago

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinter…

▾ Sunlitpython · pythonEPSS 0.16%via NVD
CVE-2026-0014Medium· 6.2PoC
6mo ago

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interactio…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-24734High· 7.5
7mo ago

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP …

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP …

▾ Twilightapache · tomcatEPSS 0.52%via NVD
CVE-2026-20627Medium· 5.5
7mo ago

An issue existed in the handling of environment variables

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, wa…

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2025-12131Medium· 6.5
7mo ago

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

▾ Sunlitsilabs · simplicity_software_development_kitEPSS 0.22%via NVD
CVE-2024-4027High· 7.5
8mo ago

A flaw was found in Undertow

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unaut…

▾ TwilightEPSS 0.36%via NVD
CWE-20 vulnerabilities (CVEs) — page 18 · VulnSea