VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-0976Low· 3.7
8mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A re…

▾ SunlitEPSS 0.40%via NVD
CVE-2025-65397Medium· 6.8
8mo ago

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges,…

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges,…

▾ Sunlitblurams · dome_flare_firmwareEPSS 0.32%via NVD
CVE-2026-21272High· 8.6
8mo ago

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could leverage this vulnerability to manipulate or inject malicious data…

▾ Twilightadobe · dreamweaverEPSS 0.23%via NVD
CVE-2026-21271High· 8.6
8mo ago

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti…

▾ Twilightadobe · dreamweaverEPSS 0.25%via NVD
CVE-2026-21268High· 8.6
8mo ago

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti…

▾ Twilightadobe · dreamweaverEPSS 0.25%via NVD
CVE-2026-20856High· 8.1
8mo ago

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.1%via NVD
CVE-2026-20812Medium· 6.5
8mo ago

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 1.1%via NVD
CVE-2026-0878High· 8.0
8mo ago

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

▾ Twilightmozilla · firefoxEPSS 0.48%via NVD
CVE-2025-12543Critical· 9.6PoC
8mo ago

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containi…

▾ Abyssalredhat · build_of_apache_camelEPSS 1.4%via NVD
CVE-2025-69288Critical· 9.1
9mo ago

Titra is open source project time tracking software

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without …

▾ Midnightkromit · titraEPSS 0.85%via NVD
CVE-2025-61822Medium· 6.2
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to …

▾ Sunlitadobe · coldfusionEPSS 0.65%via NVD
CVE-2025-61812High· 8.4
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require…

▾ Twilightadobe · coldfusionEPSS 4.7%via NVD
CVE-2025-61809Critical· 9.1
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures…

▾ Midnightadobe · coldfusionEPSS 0.66%via NVD
CVE-2025-62455High· 7.8
9mo ago

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.47%via NVD
CVE-2025-12945Low· 2.4
9mo ago

An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modif…

An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modif…

▾ Sunlitnetgear · r7000p_firmwareEPSS 1.1%via NVD
CVE-2025-48566High· 7.8
9mo ago

In multiple locations, there is a possible permission bypass due to a confused deputy

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.13%via NVD
CVE-2024-3884High· 7.5
9mo ago

A flaw was found in Undertow that can cause remote denial of service attacks

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded…

▾ TwilightEPSS 1.4%via NVD
CVE-2025-26858High· 8.6
10mo ago

A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted set of network packets can lead to denial of service. An attacker can send a sequence of unauthenticated pac…

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.65%via NVD
CVE-2025-13805Low· 3.7
10mo ago

A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT

A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoin…

▾ SunlitEPSS 0.37%via NVD
CVE-2025-13762None
10mo ago

Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: befor…

Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: befor…

▾ SunlitEPSS 0.14%via NVD
CVE-2025-43458Medium· 4.3
10mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously craf…

▾ Sunlitapple · safariEPSS 0.57%via NVD
CVE-2025-43365Low· 2.8
10mo ago

A denial-of-service issue was addressed with improved input validation

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26 and iPadOS 26. An unprivileged process may be able to terminate a root processes.

▾ Sunlitapple · ipadosEPSS 0.12%via NVD
CVE-2025-11226None
12mo ago

ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuratio…

ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuratio…

▾ SunlitEPSS 0.19%via NVD
CVE-2025-59940Medium· 6.5
12mo ago

mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders (C…

There is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.

▾ SunlitRed Hat · Multicluster Engine for KubernetesEPSS 0.34%via CSAF
CVE-2025-10155High· 7.8
1y ago

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTo…

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTo…

▾ Twilightmmaitre314 · picklescanEPSS 0.85%via NVD
CVE-2025-9467Medium· 5.3
1y ago

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that …

▾ Sunlitvaadin · com.vaadin:vaadinEPSS 0.39%via NVD
CVE-2025-57220Medium· 5.3
1y ago

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

▾ Sunlittenda · ac10_firmwareEPSS 0.80%via NVD
CVE-2025-9195Medium· 4.4
1y ago

Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a Denial of Service

Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a Denial of Service

▾ SunlitEPSS 0.13%via NVD
CVE-2025-34161High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell …

▾ Midnightcoollabs · coolifyEPSS 3.0%via NVD
CVE-2025-34159High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Do…

▾ Midnightcoollabs · coolifyEPSS 0.96%via NVD
CWE-20 vulnerabilities (CVEs) — page 19 · VulnSea